CVE-2021-22555
Last modified
CVE-2021-22555 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space. CISA has confirmed active exploitation in the wild. EPSS estimates a 78.68% chance of exploitation in the next 30 days.
Description
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Netapp | C400 Firmware | All versions |
| Netapp | C250 Firmware | All versions |
| Netapp | H410c Firmware | All versions |
| Netapp | H300s Firmware | All versions |
| Netapp | H500s Firmware | All versions |
| Netapp | H700s Firmware | All versions |
| Netapp | H410s Firmware | All versions |
| Linux | Linux Kernel | >= 2.6.19, < 4.4.267 |
| Linux | Linux Kernel | >= 4.5, < 4.9.267 |
| Linux | Linux Kernel | >= 4.10, < 4.14.231 |
| Linux | Linux Kernel | >= 4.15, < 4.19.188 |
| Linux | Linux Kernel | >= 4.20, < 5.4.113 |
| Linux | Linux Kernel | >= 5.5, < 5.10.31 |
| Linux | Linux Kernel | >= 5.11, < 5.12 |
| Brocade | Fabric Operating System | All versions |
| Netapp | Fas 8300 Firmware | All versions |
| Netapp | Fas 8700 Firmware | All versions |
| Netapp | Aff A400 Firmware | All versions |
| Netapp | Aff A250 Firmware | All versions |
| Netapp | Aff 500f Firmware | All versions |
| Netapp | H610c Firmware | All versions |
| Netapp | H610s Firmware | All versions |
| Netapp | H615c Firmware | All versions |
| Netapp | Cloud Backup | All versions |
| Netapp | Hci Management Node | All versions |
| Netapp | Solidfire | All versions |
| Netapp | Solidfire Baseboard Management Controller | All versions |
References
- http://packetstormsecurity.com/files/163528/Linux-Kernel-Netfilter-Heap-Out-Of-Bounds-Write.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/163878/Kernel-Live-Patch-Security-Notice-LSN-0080-1.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/164155/Kernel-Live-Patch-Security-Notice-LSN-0081-1.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/164437/Netfilter-x_tables-Heap-Out-Of-Bounds-Write-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.htmlExploit, Third Party Advisory, VDB Entry
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=9fa492cdc160cd27ce1046cb36f47d3b2b1efa21Mailing List, Patch, Vendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=b29c457a6511435960115c0f548c4360d5f4801dMailing List, Patch, Vendor Advisory
- https://github.com/google/security-research/security/advisories/GHSA-xxx5-8mvq-3528Exploit, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0010/Third Party Advisory
- http://packetstormsecurity.com/files/163528/Linux-Kernel-Netfilter-Heap-Out-Of-Bounds-Write.htmlThird Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/163878/Kernel-Live-Patch-Security-Notice-LSN-0080-1.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/164155/Kernel-Live-Patch-Security-Notice-LSN-0081-1.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/164437/Netfilter-x_tables-Heap-Out-Of-Bounds-Write-Privilege-Escalation.htmlExploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.htmlExploit, Third Party Advisory, VDB Entry
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=9fa492cdc160cd27ce1046cb36f47d3b2b1efa21Mailing List, Patch, Vendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=b29c457a6511435960115c0f548c4360d5f4801dMailing List, Patch, Vendor Advisory
- https://github.com/google/security-research/security/advisories/GHSA-xxx5-8mvq-3528Exploit, Third Party Advisory
- https://security.netapp.com/advisory/ntap-20210805-0010/Third Party Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-22555US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2021-22555?
How severe is CVE-2021-22555?
How do I fix CVE-2021-22555?
Are you affected by CVE-2021-22555?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
