CVE Feed

    Dashboard / CVE / CVE-2021-22555

    CVE-2021-22555

    A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

    Published:Jul 7, 2021
    Last Modified:Dec 30, 2025
    EPS:Jul 7, 2021
    EPSS Score:0.85339
    CVSS Score:8.3

    CISA Notification

    Description

    A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

    Required Action:

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Notes:

    No extra notes provided.

    Due Date
    Oct 27, 2025
    319 days ago
    Alert Date
    Oct 6, 2025
    340 days ago

    Affected Products

    Vendor
    Brocade
    Product
    Fabric Operating System
    Vendor
    Linux
    Product
    Linux Kernel
    Vendor
    Netapp
    Product
    Aff 500f
    Vendor
    Netapp
    Product
    Aff 500f Firmware
    Vendor
    Netapp
    Product
    Aff A250
    Vendor
    Netapp
    Product
    Aff A250 Firmware
    Vendor
    Netapp
    Product
    Aff A400
    Vendor
    Netapp
    Product
    Aff A400 Firmware
    Vendor
    Netapp
    Product
    C250
    Vendor
    Netapp
    Product
    C250 Firmware
    Vendor
    Netapp
    Product
    C400
    Vendor
    Netapp
    Product
    C400 Firmware
    Vendor
    Netapp
    Product
    Cloud Backup
    Vendor
    Netapp
    Product
    Fas 8300
    Vendor
    Netapp
    Product
    Fas 8300 Firmware
    Vendor
    Netapp
    Product
    Fas 8700
    Vendor
    Netapp
    Product
    Fas 8700 Firmware
    Vendor
    Netapp
    Product
    H300s
    Vendor
    Netapp
    Product
    H300s Firmware
    Vendor
    Netapp
    Product
    H410c
    Vendor
    Netapp
    Product
    H410c Firmware
    Vendor
    Netapp
    Product
    H410s
    Vendor
    Netapp
    Product
    H410s Firmware
    Vendor
    Netapp
    Product
    H500s
    Vendor
    Netapp
    Product
    H500s Firmware
    Vendor
    Netapp
    Product
    H610c
    Vendor
    Netapp
    Product
    H610c Firmware
    Vendor
    Netapp
    Product
    H610s
    Vendor
    Netapp
    Product
    H610s Firmware
    Vendor
    Netapp
    Product
    H615c
    Vendor
    Netapp
    Product
    H615c Firmware
    Vendor
    Netapp
    Product
    H700s
    Vendor
    Netapp
    Product
    H700s Firmware
    Vendor
    Netapp
    Product
    Hci Management Node
    Vendor
    Netapp
    Product
    Solidfire
    Vendor
    Netapp
    Product
    Solidfire Baseboard Management Controller
    Vendor
    Redhat
    Product
    Enterprise Linux
    Vendor
    Redhat
    Product
    Rhel Aus
    Vendor
    Redhat
    Product
    Rhel E4s
    Vendor
    Redhat
    Product
    Rhel Eus
    Vendor
    Redhat
    Product
    Rhel Extras Rt
    Vendor
    Redhat
    Product
    Rhel Tus
    Vendor
    Redhat
    Product
    Rhev Hypervisor

    Exploits

    http://packetstormsecurity.com/files/163878/Kernel-Live-Patch-Security-Notice-LSN-0080-1.htmlhttp://packetstormsecurity.com/files/164155/Kernel-Live-Patch-Security-Notice-LSN-0081-1.htmlhttp://packetstormsecurity.com/files/164437/Netfilter-x_tables-Heap-Out-Of-Bounds-Write-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.htmlhttps://github.com/google/security-research/security/advisories/GHSA-xxx5-8mvq-3528http://packetstormsecurity.com/files/163878/Kernel-Live-Patch-Security-Notice-LSN-0080-1.htmlhttp://packetstormsecurity.com/files/164155/Kernel-Live-Patch-Security-Notice-LSN-0081-1.htmlhttp://packetstormsecurity.com/files/164437/Netfilter-x_tables-Heap-Out-Of-Bounds-Write-Privilege-Escalation.htmlhttp://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.htmlhttps://github.com/google/security-research/security/advisories/GHSA-xxx5-8mvq-3528https://www.exploit-db.com/exploits/50135https://github.com/cgwalters/container-cve-2021-22555https://github.com/daletoniris/CVE-2021-22555-esc-privhttps://github.com/glutton-su/CVE-2021-22555https://github.com/JoneyJunior/cve-2021-22555https://github.com/letsr00t/-2021-LOCALROOT-CVE-2021-22555https://github.com/letsr00t/CVE-2021-22555https://github.com/masjohncook/netsec-projecthttps://github.com/pashayogi/CVE-2021-22555https://github.com/Spydomain/CVE-2021-22555-Pochttps://github.com/tukru/CVE-2021-22555https://github.com/veritas501/CVE-2021-22555-PipeVersionhttps://github.com/WhatsWrongAndWhy/CVE-2021-22555https://github.com/xyjl-ly/CVE-2021-22555-Exploit

    Common Weakness Enumeration

    Common Attack Pattern Enumeration and Classification (CAPEC)

    No CAPEC recorded yet

    Related CVEs

    References

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High