CVE-2021-22600 PUBLISHED KEV

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

EPSS 0.14% · 34.7th percentile

Risk Scores

EPSS Score
0.14%
34.7th percentile

Affected Products

VendorProductVersions
Ubuntu:18.04:LTSlinux-oracle-5.35.3.0-1018.20~18.04.1, 5.3.0-1016.18~18.04.1, 5.3.0-1014.15~18.04.1
Ubuntu:20.04:LTSlinux-azure-5.130, 5.13.0-1009.10~20.04.2, 5.13.0-1012.14~20.04.1
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-aws-fips4.15.0-2025.25, 4.15.0-2026.26, 4.15.0-2027.27
Ubuntu:18.04:LTSlinux-gcp5.0.0-1034.35, 0, 4.15.0-1014.14
Ubuntu:20.04:LTSlinux-oem-5.65.6.0-1034.36, 5.6.0-1056.60, 5.6.0-1055.59
Ubuntu:Pro:FIPS-updates:18.04:LTSlinux-azure-fips4.15.0-2034.38, 4.15.0-2035.39, 4.15.0-2036.40
Ubuntu:Pro:16.04:LTSlinux-hwe4.15.0-36.39~16.04.1, 4.15.0-122.124~16.04.1, 4.15.0-120.122~16.04.1
Ubuntu:18.04:LTSlinux-kvm4.15.0-1089.91, 4.15.0-1099.101, 4.15.0-1100.102
Ubuntu:20.04:LTSlinux-raspi25.3.0-1007.8, 5.3.0-1017.19, 5.4.0-1004.4
Ubuntu:18.04:LTSlinux-gke-4.154.15.0-1052.55, 0, 4.15.0-1030.32
Ubuntu:20.04:LTSlinux-kvm5.4.0-1051.53, 5.4.0-1015.15, 5.4.0-1011.11
Ubuntu:20.04:LTSlinux-aws-5.85.8.0-1042.44~20.04.1, 5.8.0-1041.43~20.04.1, 5.8.0-1038.40~20.04.1
Ubuntu:Pro:16.04:LTSlinux-aws-hwe4.15.0-1118.125~16.04.1, 4.15.0-1048.50~16.04.1, 4.15.0-1050.52~16.04.1
Ubuntu:Pro:FIPS:20.04:LTSlinux-aws-fips0, 5.4.0-1021.21+fips2
Ubuntu:18.04:LTSlinux-azure-4.154.15.0-1103.114, 4.15.0-1104.116, 4.15.0-1106.118
Ubuntu:Pro:16.04:LTSlinux-gcp4.15.0-1058.62, 4.15.0-1055.59, 4.15.0-1052.56
Ubuntu:Pro:FIPS-updates:20.04:LTSlinux-gcp-fips0, 5.4.0-1021.21+fips1
Ubuntu:20.04:LTSlinux-ibm0, 5.4.0-1005.6, 5.4.0-1006.7
Ubuntu:18.04:LTSlinux-oracle-5.40, 5.4.0-1044.47~18.04.1, 5.4.0-1063.67~18.04.1
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0

…and 68 more

Timeline

References

Open in Interactive Console →