CVE-2021-22555
Summary
| CVE | CVE-2021-22555 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2021-07-07 12:15:00 UTC |
| Updated | 2022-03-31 19:15:00 UTC |
| Description | A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space |
Risk And Classification
EPSS: 0.852390000 probability, percentile 0.993520000 (date 2026-04-01)
CISA KEV: Listed on 2025-10-06; due 2025-10-27; ransomware use Unknown
Problem Types: CWE-787
CISA Known Exploited Vulnerability
| Vendor | Linux |
|---|---|
| Product | Kernel |
| Name | Linux Kernel Heap Out-of-Bounds Write Vulnerability |
| Required Action | Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. |
| Notes | https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=9fa492cdc160cd27ce1046cb36f47d3b2b1efa21 ; https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=b29c457a6511435960115c0f548c4360d5f4801d ; https://security.netapp.com/advisory/ntap-20210805-0010/ ; https://github.com/google/security-research/security/advisories/GHSA-xxx5-8mvq-3528 ; https://nvd.nist.gov/vuln/detail/CVE-2021-22555 |
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Brocade | Fabric Operating System | - | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Hardware | Netapp | Aff 500f | - | All | All | All |
| Operating System | Netapp | Aff 500f Firmware | - | All | All | All |
| Hardware | Netapp | Aff A250 | - | All | All | All |
| Operating System | Netapp | Aff A250 Firmware | - | All | All | All |
| Hardware | Netapp | Aff A400 | - | All | All | All |
| Operating System | Netapp | Aff A400 Firmware | - | All | All | All |
| Hardware | Netapp | Fas 8300 | - | All | All | All |
| Operating System | Netapp | Fas 8300 Firmware | - | All | All | All |
| Hardware | Netapp | Fas 8700 | - | All | All | All |
| Operating System | Netapp | Fas 8700 Firmware | - | All | All | All |
| Hardware | Netapp | H610c | - | All | All | All |
| Operating System | Netapp | H610c Firmware | - | All | All | All |
| Hardware | Netapp | H610s | - | All | All | All |
| Operating System | Netapp | H610s Firmware | - | All | All | All |
| Hardware | Netapp | H615c | - | All | All | All |
| Operating System | Netapp | H615c Firmware | - | All | All | All |
| Application | Netapp | Hci Management Node | - | All | All | All |
| Application | Netapp | Solidfire | - | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Kernel Live Patch Security Notice LSN-0080-1 ≈ Packet Storm | MISC | packetstormsecurity.com | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | |
| CVE-2021-22555 Linux Kernel Vulnerability in NetApp Products | NetApp Product Security | CONFIRM | security.netapp.com | |
| Kernel Live Patch Security Notice LSN-0081-1 ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Netfilter x_tables Heap Out-Of-Bounds Write / Privilege Escalation ≈ Packet Storm | MISC | packetstormsecurity.com | |
| Linux Kernel Netfilter Heap Out-Of-Bounds Write ≈ Packet Storm | MISC | packetstormsecurity.com | |
| github.com/google/security-research/security/advisories/GHSA-xxx5-8mvq-3528 | MISC | github.com | |
| Kernel Live Patch Security Notice LSN-0083-1 ≈ Packet Storm | MISC | packetstormsecurity.com | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MISC | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
| CISA Known Exploited Vulnerabilities catalog | CISA | www.cisa.gov | kev |
Vendor Comments And Credit
Discovery Credit
LEGACY: Andy Nguyen
Legacy QID Mappings
- 159329 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-3057)
- 159332 Oracle Enterprise Linux Security Update for Unbreakable Enterprise kernel (ELSA-2021-9395)
- 159375 Oracle Enterprise Linux Security Update for kernel (ELSA-2021-3327)
- 179640 Debian Security Update for linux (CVE-2021-22555)
- 239541 Red Hat Update for kernel (RHSA-2021:3057)
- 239542 Red Hat Update for kpatch-patch (RHSA-2021:3044)
- 239543 Red Hat Update for kernel-rt (RHSA-2021:3088)
- 239566 Red Hat Update for kpatch-patch (RHSA-2021:3181)
- 239570 Red Hat Update for kernel (RHSA-2021:3173)
- 239592 Red Hat Update for kpatch-patch (RHSA-2021:3381)
- 239593 Red Hat Update for kpatch-patch (RHSA-2021:3380)
- 239594 Red Hat Update for kernel-rt (RHSA-2021:3375)
- 239599 Red Hat Update for kernel (RHSA-2021:3363)
- 239602 Red Hat Update for kernel-rt (RHSA-2021:3328)
- 239603 Red Hat Update for kernel (RHSA-2021:3327)
- 257109 CentOS Security Update for kernel (CESA-2021:3327)
- 352831 Amazon Linux Security Advisory for kernel: ALAC2012-2021-030
- 352832 Amazon Linux Security Advisory for kmod-sfc: ALAC2012-2021-031
- 352833 Amazon Linux Security Advisory for kmod-mlx5: ALAC2012-2021-032
- 376748 F5 BIG-IP Application Security Manager (ASM), Local Traffic Manager (LTM), Access Policy Manager (APM) Linux kernel Vulnerability (K06524534)
- 390220 Oracle Managed Virtualization (VM) Server for x86 Security Update for kernel (OVMSA-2021-0025)
- 670707 EulerOS Security Update for kernel (EulerOS-SA-2021-2465)
- 670772 EulerOS Security Update for kernel (EulerOS-SA-2021-2530)
- 670796 EulerOS Security Update for kernel (EulerOS-SA-2021-2554)
- 671047 EulerOS Security Update for kernel (EulerOS-SA-2021-2588)
- 671051 EulerOS Security Update for kernel (EulerOS-SA-2021-2663)
- 750844 SUSE Enterprise Linux Security Update for kernel (SUSE-SU-2021:2407-1)
- 750847 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:2409-1)
- 750848 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2416-1)(Sequoia)
- 750851 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:2415-1)(Sequoia)
- 750864 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2421-1)
- 750868 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2427-1)
- 750869 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2422-1)
- 750877 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:2427-1)
- 750880 SUSE Enterprise Linux Security Update for the Linux Kernel (SUSE-SU-2021:2451-1)
- 750887 OpenSUSE Security Update for the Linux Kernel (openSUSE-SU-2021:1076-1)
- 750899 SUSE Enterprise Linux Security Update for the Linux Kernel (Live Patch 36 for SLE 12 SP3) (SUSE-SU-2021:2538-1)
- 940353 AlmaLinux Security Update for kernel (ALSA-2021:3057)
- 960074 Rocky Linux Security Update for kernel (RLSA-2021:3057)
- 960852 Rocky Linux Security Update for kernel-rt (RLSA-2021:3088)