Linux Kernel security update-CVE-2021-22600
NAME
Linux Kernel Organization – Linux Kernel
- Platforms Affected:
Linux Kernel - Risk Level:
medium - CVE Type:
Double free
DESCRIPTION
CVE-2021-22600 is a double free vulnerability impacting multiple versions of Linux Kernel. A proof of concept (PoC) was not observed publicly or in the underground. Security researchers at the Cybersecurity and Infrastructure Security Agency (CISA) claimed the vulnerability was actively exploited in the wild.
CVSS Information:
- CVSS 2.0 SCORE: 7.2
- CVSS 3.0 SCORE: 7.8
- Exploit Disclosed in the Public:
true - Exploit Weaponised:
true - PoC Link:
hXXps://www[.]cisa[.]gov/known-exploited-vulnerabilities-catalog
MITIGATION
Linux Kernel Organization addressed the vulnerability in a software development platform saved commit change with a patch.
- Reference Link:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit?id=ec6af094ea28f0f2dda1a6a33b14cd57e36a9755 - Patch Available:
available
If you like the site, please consider joining the telegram channel and supporting us on Patreon using the button below.