CVE-2021-22555

Linux Kernel — Linux Kernel Heap Out-of-Bounds Write Vulnerability

Severity
critical
Actively exploited
actively exploited (KEV)
99.6 %
Critical — model predicts very high exploitation likelihood in the next 30 days.
Published
2025-10-06 00:00 UTC
CWE-787, CWE-787

Weakness classes (CWE)

  • CWE-787Base

    Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →
  • CWE-787Base

    Out-of-bounds Write

    The product writes data past the end, or before the beginning, of the intended buffer.

    cwe.mitre.org →

Description

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

Source: CISA_KEV

Affected operating systems

  • linux

    linux / linux_kernel

  • other

    netapp / aff_500f_firmware

  • other

    netapp / aff_a250_firmware

  • other

    netapp / aff_a400_firmware

  • other

    netapp / c250_firmware

  • other

    netapp / c400_firmware

  • other

    brocade / fabric_operating_system

  • other

    netapp / fas_8300_firmware

  • other

    netapp / fas_8700_firmware

  • other

    netapp / h300s_firmware

  • other

    netapp / h410c_firmware

  • other

    netapp / h410s_firmware

  • other

    netapp / h500s_firmware

  • other

    netapp / h610c_firmware

  • other

    netapp / h610s_firmware

  • other

    netapp / h615c_firmware

  • other

    netapp / h700s_firmware

Public exploit references

Public proof-of-concepts and detection templates for this vulnerability. Maturity ranges from reported PoCs through working detection scripts up to fully weaponized exploit modules. NEOSEC mirrors the code internally for forensic analysis; externally we only link to the original sources.

References & sources