vulnerability

Oracle Linux: CVE-2021-22600: ELSA-2022-9274: Unbreakable Enterprise kernel-container security update (IMPORTANT) (Multiple Advisories)

Severity
6
CVSS
(AV:L/AC:H/Au:S/C:C/I:C/A:C)
Published
Dec 15, 2021
Added
Apr 12, 2022
Modified
Feb 21, 2025

Description

A double free bug in packet_set_ring() in net/packet/af_packet.c can be exploited by a local user through crafted syscalls to escalate privileges or deny service. We recommend upgrading kernel past the effected versions or rebuilding past ec6af094ea28f0f2dda1a6a33b14cd57e36a9755
A double-free flaw was found in the Linux kernel’s packet protocol subsystem in the way a user call triggers the packet_set_ring() function of the net/packet/af_packet.c. This flaw allows a local user to crash or escalate their privileges on the system.

Solution

oracle-linux-upgrade-kernel-uek
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.