CVE-2021-22555

Linux Kernel — Linux Kernel Heap Out-of-Bounds Write Vulnerability

Severity
critical
Aktiv ausgenutzt
aktiv ausgenutzt (KEV)
99.6 %
Kritisch — Modell sagt sehr hohe Ausnutzungs-Wahrscheinlichkeit in den nächsten 30 Tagen.
Veröffentlicht
2025-10-06 00:00 UTC
CWE-787, CWE-787

Weakness-Klassen (CWE)

  • CWE-787Base

    Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →
  • CWE-787Base

    Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

Beschreibung

Der Linux Kernel enthält eine Heap-Überlauf-Schwachstelle mit Schreibzugriff außerhalb der Grenzen, die es einem Angreifer ermöglichen könnte, Rechte auszuweiten oder einen Denial-of-Service-Angriff durchzuführen (durch Speicherbeschädigung im Heap) über User-Namespaces.

Quelle: CISA_KEV

Betroffene Betriebssysteme

  • linux

    linux / linux_kernel

  • other

    netapp / aff_500f_firmware

  • other

    netapp / aff_a250_firmware

  • other

    netapp / aff_a400_firmware

  • other

    netapp / c250_firmware

  • other

    netapp / c400_firmware

  • other

    brocade / fabric_operating_system

  • other

    netapp / fas_8300_firmware

  • other

    netapp / fas_8700_firmware

  • other

    netapp / h300s_firmware

  • other

    netapp / h410c_firmware

  • other

    netapp / h410s_firmware

  • other

    netapp / h500s_firmware

  • other

    netapp / h610c_firmware

  • other

    netapp / h610s_firmware

  • other

    netapp / h615c_firmware

  • other

    netapp / h700s_firmware

Öffentliche Exploit-Referenzen

Öffentliche Proof-of-Concepts und Detection-Templates für diese Schwachstelle. Die Reife reicht von gemeldeten PoCs über funktionsfähige Detection-Skripte bis hin zu vollständig waffenfähigen Exploit-Modulen. NEOSEC mirrort den Code intern für forensische Analysen; nach außen verlinken wir ausschließlich auf die Original-Quellen.

Quellen & Referenzen