CVE-2021-22600 is a double free vulnerability in the Linux kernel's AF_PACKET implementation, specifically in packet_set_ring() in net/packet/af_packet.c. A local user can trigger the flaw via crafted system calls that manipulate packet ring buffer handling, causing the same memory to be freed more than once. This memory corruption condition can lead to kernel instability and, depending on exploitation, may be leveraged for privilege escalation. The affected component is the Linux kernel networking subsystem handling packet sockets.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
This repository contains a comprehensive exploit toolkit targeting CVE-2021-22600, a Linux kernel vulnerability known as DirtyPagetable. The exploit is implemented in C and consists of several variants and techniques, including 'Spray and Pray', cross-cache side-channel attacks, and SLUBStick-inspired methods. The main goal of the exploit is to achieve local privilege escalation by corrupting kernel memory structures (notably signalfd_ctx and seq_operations objects) through heap spraying and manipulation of packet sockets (AF_PACKET, PACKET_RX_RING, etc.). The exploit works by creating user and network namespaces, manipulating kernel heap allocations via signalfd and packet socket options, and ultimately overlapping kernel objects to gain arbitrary write access. The payload specifically targets /etc/passwd, overwriting the root password to a known value, thus enabling root access for the attacker. The codebase is modular, with separate files for environment setup, heap spraying, and the core exploitation logic. Several files implement different exploitation strategies, all converging on the same privilege escalation goal. Key fingerprintable endpoints include /etc/passwd (target for privilege escalation), /proc/self/fdinfo/<fd> (used for kernel object state leakage), and various /proc files for namespace and heap manipulation. The exploit requires local access and is not a remote exploit. It is operational and provides a working payload for root access if the target is vulnerable.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
2 sources tracked across advisories and community write-ups. News coverage will land here when it surfaces.
No news coverage yet. Advisories and community discussion only.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.