CVE-2021-22600

Linux Kernel Kernel

Published 26 Jan 2022 · updated 17 Jun 2026 · Analyzed

7.0 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 11 Apr 2022, with a remediation deadline of 2 May 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

References