boxscore/security
CVE · referencelatest edition

Reference page — cumulative record through Sunday, October 4, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.

CVE-2021-22600

Linux Kernel Kernel — Double Free in net/packet/af_packet.c leading to priviledge escalation
  AV  AC  PR  UI  S  C  I  A   CVSS    EPSS   %ile   KEV
   L   H   L   R  C  L  L  H    6.6   .0659   93.6   YES
AFFECTED
  Product  Versions       Fixed
  Kernel   unspecified –  —
TIMELINE
  Jan 5   Reserved by Google
  Jan 26  Published (CNA: Google)
  Apr 11  Added to CISA KEV, remediation due 2022-05-02
CWE-415 · CNA: Google · CVSS v3.1 · 5 references · KEV due May 2, 2022

Description

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755

Lifecycle

Complete event history — 3 events, chronological
DateEventDetail
January 5, 2021ReservedReserved by Google
January 26, 2022PublishedPublished (CNA: Google)
April 11, 2022KEV ADDEDAdded to CISA KEV, remediation due 2022-05-02

Affected

Affected products and packages — 1 row
VendorProduct / PackageEcosystemVersion introducedFixed
Linux KernelKernel—unspecified—

Weaknesses

CWE-415

References (5)

Related

Authoritative record: CVE-2021-22600 at cve.org

Vendors: linux

Weaknesses: CWE-415

About this page

This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2021-22600 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Sunday, October 4, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.