CVE-2021-22555
Last modified
CVE-2021-22555 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space. CISA has confirmed active exploitation in the wild. EPSS estimates a 78.68% chance of exploitation in the next 30 days.
Description
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
Metrics
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netapp | C400 Firmware | All versions |
| Netapp | C250 Firmware | All versions |
| Netapp | H410c Firmware | All versions |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H410s Firmware | All versions |
| Linux | Linux Kernel | >= 2.6.19, < 4.4.267 |
| Linux | Linux Kernel | >= 4.5, < 4.9.267 |
| Linux | Linux Kernel | >= 4.10, < 4.14.231 |
| Linux | Linux Kernel | >= 4.15, < 4.19.188 |
| Linux | Linux Kernel | >= 4.20, < 5.4.113 |
| Linux | Linux Kernel | >= 5.5, < 5.10.31 |
| Linux | Linux Kernel | >= 5.11, < 5.12 |
| Brocade | Fabric Operating System | All versions |
| Netapp | Fas 8300 Firmware | All versions |
| Netapp | Fas 8700 Firmware | All versions |
| Netapp | Aff A400 Firmware | All versions |
| Netapp | Aff A250 Firmware | All versions |
| Netapp | Aff 500f Firmware | All versions |
| Netapp | H610c Firmware | All versions |
| Netapp | H610s Firmware | All versions |
| Netapp | H615c Firmware | All versions |
| Netapp | Cloud Backup | All versions |
| Netapp | Hci Management Node | All versions |
| Netapp | Solidfire | All versions |
| Netapp | Solidfire Baseboard Management Controller | All versions |
References
- https://packetstormsecurity.com/files/163528/Linux-Kernel-Netfilter-Heap-Out-Of-Bounds-Write.htmlThird Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/163878/Kernel-Live-Patch-Security-Notice-LSN-0080-1.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/164155/Kernel-Live-Patch-Security-Notice-LSN-0081-1.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/164437/Netfilter-x_tables-Heap-Out-Of-Bounds-Write-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.htmlExploit, Third Party Advisory, VDB Entry
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=9fa492cdc160cd27ce1046cb36f47d3b2b1efa21Mailing List, Patch, Vendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=b29c457a6511435960115c0f548c4360d5f4801dMailing List, Patch, Vendor Advisory
- https://github.com/google/security-research/security/advisories/GHSA-xxx5-8mvq-3528Exploit, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0010/Third Party Advisory
- https://packetstormsecurity.com/files/163528/Linux-Kernel-Netfilter-Heap-Out-Of-Bounds-Write.htmlThird Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/163878/Kernel-Live-Patch-Security-Notice-LSN-0080-1.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/164155/Kernel-Live-Patch-Security-Notice-LSN-0081-1.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/164437/Netfilter-x_tables-Heap-Out-Of-Bounds-Write-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- https://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.htmlExploit, Third Party Advisory, VDB Entry
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=9fa492cdc160cd27ce1046cb36f47d3b2b1efa21Mailing List, Patch, Vendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=b29c457a6511435960115c0f548c4360d5f4801dMailing List, Patch, Vendor Advisory
- https://github.com/google/security-research/security/advisories/GHSA-xxx5-8mvq-3528Exploit, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0010/Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22555US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-22555?
How severe is CVE-2021-22555?
How do I fix CVE-2021-22555?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-22548An attacker can change the pointer to untrusted memory to po…7.8
- CVE-2021-22549An attacker can modify the address to point to trusted memor…7.8
- CVE-2021-2255Vulnerability in the Oracle Service Contracts product of Ora…8.1
- CVE-2021-22550An attacker can modify the pointers in enclave memory to ove…7.8
- CVE-2021-22552An untrusted memory read vulnerability in Asylo versions up …5.5
- CVE-2021-22553Any git operation is passed through Jetty and a session is c…7.5
- CVE-2021-22556The Security Team discovered an integer overflow bug that al…7.8
- CVE-2021-22557SLO generator allows for loading of YAML files that if craft…7.8
- CVE-2021-2256Vulnerability in the Oracle Storage Cloud Software Appliance…10
- CVE-2021-22563Invalid JPEG XL images using libjxl can cause an out of boun…4.4
- CVE-2021-22564For certain valid JPEG XL images with a size slightly larger…5.5
- CVE-2021-22565An attacker could prematurely expire a verification code, ma…6.5
Are you affected by CVE-2021-22555?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
