7.2

CVE-2021-22600

Warnung

Double Free in net/packet/af_packet.c leading to priviledge escalation

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Netapp ≫ 8300 Firmware Version -
   Netapp ≫ 8300 Version -
Netapp ≫ 8700 Firmware Version -
   Netapp ≫ 8700 Version -
Netapp ≫ A400 Firmware Version -
   Netapp ≫ A400 Version -
Netapp ≫ C400 Firmware Version -
   Netapp ≫ C400 Version -
Linux ≫ Linux Kernel Version >= 4.14.175 < 4.14.259
Linux ≫ Linux Kernel Version >= 4.19.114 < 4.19.222
Linux ≫ Linux Kernel Version >= 5.4.29 < 5.4.168
Linux ≫ Linux Kernel Version >= 5.5.14 < 5.10.88
Linux ≫ Linux Kernel Version >= 5.11 < 5.15.11
Debian ≫ Debian Linux Version 9.0
Debian ≫ Debian Linux Version 10.0
Netapp ≫ H410c Firmware Version -
   Netapp ≫ H410c Version -
Netapp ≫ H300s Firmware Version -
   Netapp ≫ H300s Version -
Netapp ≫ H500s Firmware Version -
   Netapp ≫ H500s Version -
Netapp ≫ H700s Firmware Version -
   Netapp ≫ H700s Version -
Netapp ≫ H410s Firmware Version -
   Netapp ≫ H410s Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login

11.04.2022: CISA Known Exploited Vulnerabilities (KEV) Catalog

Linux Kernel Privilege Escalation Vulnerability

Schwachstelle

Linux Kernel contains a flaw in the packet socket (AF_PACKET) implementation which could lead to incorrectly freeing memory. A local user could exploit this for denial-of-service (DoS) or possibly for privilege escalation.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.87% 0.925
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
cve-coordination@google.com 6.6 0.8 5.3
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:H
CWE-415 Double Free

The product calls free() twice on the same memory address.

https://lists.debian.org/debian-lts-announce/2022/03/msg00012.html
Third Party Advisory
Mailing List
https://www.debian.org/security/2022/dsa-5096
Third Party Advisory
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
Patch
Mailing List
https://security.netapp.com/advisory/ntap-20230110-0002/
Third Party Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22600
US Government Resource