HIGH

CVE-2021-22555

Linux Linux Kernel 2021-07-07 CVSS v3.1
CVSS
7.8
KEV

Description

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

Summary dbcve.org

Heap out-of-bounds write vulnerability in net/netfilter/x_tables.c affecting Linux kernels since v2.6.19-rc1 allows local attackers to gain elevated privileges or cause denial of service via heap memory corruption through user namespace interaction.

Mitigation

Apply the upstream kernel patch or update to a kernel version containing the fix (Linux 5.10.13, 5.4.97, or later). This is a privilege escalation vulnerability requiring local access but with high impact due to heap corruption.

Proof of Concept
Patch Commit

Weakness (CWE)

CWE-787 Out-of-bounds Write

EPSS Score

78.68%
Probability of exploitation in next 30 days
99.6th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE