CVE-2021-22555 is a heap out-of-bounds write vulnerability in the Linux kernel's netfilter x_tables component, affecting Linux since version 2.6.19-rc1, as well as products from Brocade and NetApp. It carries a high CVSS score of 7.8, indicating that a local attacker with low privileges can achieve privilege escalation or cause a denial of service with low attack complexity. This vulnerability is actively exploited in the wild, with public exploit code available (e.g., Metasploit, ExploitDB), and has garnered significant community discussion and media coverage, highlighting its critical nature.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:c400_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:c250_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:h500s_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
Jul 7, 2021kernel: out-of-bounds write in xt_compat_target_from_user() in net/netfilter/x_tables.c
Jul 7, 2021Runc container breakout vulnerability (CVE-2021-22555)
runc container breakout vulnerability (CVE-2021-22555)