Evidence dossier
CVE-2021-22600
Double Free in net/packet/af_packet.c leading to priviledge escalation
Exploited in the wild (CISA KEV since Apr 11, 2022). NVD reports CVSS 3.1 7.0. Severity assessments differ within at least one CVSS version. EPSS estimates 6.1% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
- State
- PUBLISHED
- Published
- Jan 26, 2022
- Updated
- Oct 21, 2025
- Evidence coverage
- 86%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAGoogleOriginal evidence ↗
Record text: Double Free in net/packet/af_packet.c leading to priviledge escalation
Inspect raw assertion
- Field
container- Value
- Double Free in net/packet/af_packet.c leading to priviledge escalation
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Linux Kernel Privilege Escalation Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Privilege Escalation Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 6.08% probability · 92.87th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.060790000000; percentile 0.928690000000
Assessments differ
Values are shown separately by source and CVSS version.
CISA KEV · catalog date Apr 11, 2022 · first observed Jul 19, 2026
FIRST EPSS · score date Aug 27, 2026 · 92.9th percentile · first observed Aug 27, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · values shown separately below
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible assertions materially conflict and remain visible side by side.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve conflict
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Double Free in net/packet/af_packet.c leading to priviledge escalation
Inspect raw assertion
- Field
container- Value
- Double Free in net/packet/af_packet.c leading to priviledge escalation
Linux Kernel Privilege Escalation Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Privilege Escalation Vulnerability
6.08% probability · 92.87th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.060790000000; percentile 0.928690000000
Applicability
Cited product scope
Grouped from 20 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
21 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "unspecified", "lessThan": "5.4.168", "versionType": "custom"}, {"status": "affected", "version": "unspecified", "lessThan": "5.10.88", "versionType": "custom"}, {"status": "affected", "version": "unspecified", "lessThan": "5.15.11", "versionType": "custom"}, {"status": "affected", "version": "unspecified", "lessThan": "5.16-rc6", "versionType": "custom"}]product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertions
cpe:2.3:o:debian:debian_linux:9.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
deece5fc-cacf-4496-a3e7-164736409252
cpe:2.3:o:debian:debian_linux:10.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
07b237a9-69a3-4a9c-9da0-4e06bd37ae73
product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9Linked exactInspect raw assertions
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 5.4.29; through excluding 5.4.168
- Match ID
feaddb96-5d2f-463e-94a1-db604cb44c44
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 4.19.114; through excluding 4.19.222
- Match ID
7a938be1-f655-40d2-9cd3-a00308b35dee
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 4
- Logic
- OR
- Version bounds
- from including 5.11; through excluding 5.15.11
- Match ID
11274e95-438a-449a-b100-01b2b0046669
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 5.5.14; through excluding 5.10.88
- Match ID
9fadfaa6-11ef-467d-b365-2e2d18304156
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 4.14.175; through excluding 4.14.259
- Match ID
a5d643c3-1a06-488d-9837-ce4011d7a22d
product-adf21f46acd88b42558081e55aee715c6127c2af20ef79a0378552b0100269d9Linked exactInspect raw assertion
cpe:2.3:h:netapp:8300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d0fd5aed-42cf-4918-b32c-d675738ef15c
product-1aa4e18a4afb4ff7085d656caca2bee1572da568869be7bcc46a9cfb231e9349Linked exactInspect raw assertion
cpe:2.3:o:netapp:8300_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4e73901f-666d-4d8b-bdfd-93dd2f70c74b
product-49489bfba02eded99aff635f634a1ede82a2bfd4d56d451dd941701c96325d40Linked exactInspect raw assertion
cpe:2.3:h:netapp:8700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ce0f11d2-b5d9-46b4-bfc5-c86bc87d516a
product-9e287f96768299bace09db46e1c03db9077c29a00c5c5242dd7651c93da4715cLinked exactInspect raw assertion
cpe:2.3:o:netapp:8700_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
34b25bef-8708-4e2c-8ba6-ebcd5267eb04
product-48dd91da3acd71d28d8a9bd54a8a8111f6533e376b55f1f4049812e21828d9edLinked exactInspect raw assertion
cpe:2.3:h:netapp:a400:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
97e94ecb-bb51-4364-bedd-8648c193196f
product-93d72bea1ccd7a3d082b406ad82c558c9bd08dd18455c38994993daac0d2c24aLinked exactInspect raw assertion
cpe:2.3:o:netapp:a400_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
04e3bd77-8915-4ffc-8483-5db5d610f829
product-550139cc27fcef7ba1a8092ed8e0597a7939e52ff1fc96f65d51bb311e46faa7Linked exactInspect raw assertion
cpe:2.3:h:netapp:c400:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ad443748-b0d1-4c1a-a62e-bd5fb5967370
product-656b98475b5116ffca73cfa0270f61023660a70cceba0dd9443fafdfb26af12bLinked exactInspect raw assertion
cpe:2.3:o:netapp:c400_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9ac7ad92-8b33-4137-a4ec-08641e4af857
product-5b787f6fb0dbffca7d5383cfa87cd93654a14ed60ccdd59abc2ba697fe7ead69Linked exactInspect raw assertion
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 7 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f9c8c20-42eb-4ab5-bd97-212deb070c43
product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419Linked exactInspect raw assertion
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6770b6c3-732e-4e22-bf1c-2d2fd610061c
product-19a4460172d592ee30b338581dced13baf393eedf54989f7303c0971a7aa6832Linked exactInspect raw assertion
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cddf61b7-ec5c-467c-b710-b89f502cd04f
product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045aLinked exactInspect raw assertion
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
234defe0-5ce5-4b0a-96b8-5d227cb8ed31
product-ae7668c0a5adbc5d6599144484fb84400193fe6c73d0e6bb570cd2a233e63b35Linked exactInspect raw assertion
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8497a4c9-8474-4a62-8331-3fe862ed4098
product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481aeLinked exactInspect raw assertion
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d0b4ad8a-f172-4558-aec6-ff424ba2d912
product-4c7f1f62606e18f71887f5954346c3f8c8376e418a089dca8282922aa180aff3Linked exactInspect raw assertion
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 8 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e63d8b0f-006e-4801-bf9d-1c001bbfb4f9
product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6aLinked exactInspect raw assertion
cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7fff7106-ed78-49ba-9ec5-b889e3685d53
product-fcd38a3bd0a96c349925cecfd0d22ecf9836f21d88da8f545d6938975aa84275Linked exactInspect raw assertion
cpe:2.3:h:netapp:h700s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b06f4839-d16a-4a61-9bb5-55b13f41e47f
product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6dLinked exactInspect raw assertion
cpe:2.3:o:netapp:h700s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
56409cec-5a1e-4450-aa42-641e459cc2af
Affected-product evidence
Accepted scope and product mapping
11 canonical links · 1 source-reported links
vendor-9c702362a97e8770255c53f324861f65f3209d35ce95f01842c69a458450f6fa · product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
334e2df0-d1f2-4cce-b1fd-e2a87d443b1a422450c6-b31b-4e2f-a395-ff6710d5bab74d1b11a0-d661-4fe0-9ea4-ddf4bcd6a8559bf50bf4-294c-4c37-a2cc-c46083f77ef8e84e9060-6125-4e4a-9710-ecd15a412689vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-1aa4e18a4afb4ff7085d656caca2bee1572da568869be7bcc46a9cfb231e9349
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
70f90835-5c85-4fd8-a71a-49fbb427b39cvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
92d89a18-0185-47ab-89cb-ba3e33305484vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0838484d-2577-4af9-856c-d15f95a2719a1b059c62-0b50-44a5-82b8-2d54a761c892vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9120f729-770b-49a6-8915-1057eff57ffevendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-656b98475b5116ffca73cfa0270f61023660a70cceba0dd9443fafdfb26af12b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
ede39688-cd3e-4a0a-b116-e380ad3982a8vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-93d72bea1ccd7a3d082b406ad82c558c9bd08dd18455c38994993daac0d2c24a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d777aec5-f1f3-475a-a13e-56582d61f504vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-9e287f96768299bace09db46e1c03db9077c29a00c5c5242dd7651c93da4715c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
96e95010-a9f4-4685-a1ba-f2bf2e6dc08fvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
cd0bc0fa-435e-436b-836a-fc15c15bc871vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481ae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
38e0a04d-82f9-4c98-b0b4-6189a8bf1441vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
1eaa7b16-1738-4ae2-b394-1558df9f0a1bCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6460a685-4a32-4255-810c-815676842450Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:HAV:L/AC:L/Au:N/C:C/I:C/A:CCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:HCVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:HDirect CVE/CNA normalized decisions
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:L/A:H- Validation
- Valid match
- Recomputed
- 6.6
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.