CVE-2021-22555

Advisory lineage Upstream: 0 Downstream: 52
Analyzed
Published: 07 Jul 2021, 11:20
Last modified:30 Dec 2025, 20:32

Vulnerability Summary

Overall Risk (default)
high
60/100
CVSS Score
8.3 HIGH
v3.1 (cve.org)
EPSS Score
85.24% CRITICAL
85% probability 0.00%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
7 found
Dark Web
Not detected

Timeline

07 Jul 2021, 11:20
Published
Vulnerability first disclosed
06 Oct 2025, 00:00
Added to CISA KEV
Linux Kernel Heap Out-of-Bounds Write Vulnerability
27 Oct 2025, 00:00
CISA Remediation Due
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
30 Dec 2025, 20:32
Last Modified
Vulnerability information updated

Description

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

CVSS Metrics

  • v3.1HIGHScore: 8.3CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • v3.1HIGHScore: 7.8CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0MEDIUMScore: 4.6AV:L/AC:L/Au:N/C:P/I:P/A:P

EPSS Trends

Current EPSS score: 85.24% Percentile: 99%

Techniques & Countermeasures

  • CWE-787Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

Affected Systems

  • brocadefabric_operating_system

    na

  • linuxlinux_kernel

    ≥ 2.6.19, < 4.4.267 | ≥ 4.5, < 4.9.267 | ≥ 4.10, < 4.14.231 | ≥ 4.15, < 4.19.188 | ≥ 4.20, < 5.4.113 | ≥ 5.5, < 5.10.31 | ≥ 5.11, < 5.12

  • netappaff_500f_firmware

    na

  • netappaff_a250_firmware

    na

  • netappaff_a400_firmware

    na

  • netappc250_firmware

    na

  • netappc400_firmware

    na

  • netappcloud_backup

    na

  • netappfas_8300_firmware

    na

  • netappfas_8700_firmware

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500s_firmware

    na

  • netapph610c_firmware

    na

  • netapph610s_firmware

    na

  • netapph615c_firmware

    na

  • netapph700s_firmware

    na

  • netapphci_management_node

    na

  • netappsolidfire

    na

References (10)