ZeroHour

CVE-2021-22555

KEV PoC ×5mass

Linux Kernel Netfilter Heap OOB Write Enables Privilege Escalation (CVE-2021-22555)

CISA: Linux Kernel Heap Out-of-Bounds Write Vulnerability

CVSS 3.1
7.8 high
EPSS
79%p100
Published
()
KEV added
AI analysis

CVE-2021-22555 is a heap out-of-bounds write (CWE-787) in the netfilter x_tables code (net/netfilter/x_tables.c) of the Linux kernel, a flaw present since version v2.6.19-rc1. A local attacker can trigger the heap memory corruption through user namespaces, meaning even unprivileged users, such as workloads running inside containers, can reach the vulnerable code path. Successful exploitation lets the attacker gain elevated kernel-level privileges, typically fully escaping a container, or crash the system in a denial of service. Affected users are essentially any Linux deployment on kernels in the affected range (distributions, cloud servers, container hosts), and CISA's product mapping additionally covers NetApp firmware for its c400/c250, H300S/H410S/H410C/H500S/H700S, FAS 8300/8700 and AFF A400 systems plus Brocade Fabric OS. The flaw has public proof-of-concept exploits (including Google security research), a high 78.7% EPSS exploitation probability over 30 days, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06, confirming exploitation in the wild.

What to do: Upgrade Linux kernels to patched versions from your distribution and apply vendor live patches where offered (Ubuntu Kernel Live Patch notices LSN-0080/0081/0083 are referenced in public advisories), and install the corresponding NetApp and Brocade firmware updates for the listed systems. Where patching must wait, restrict creation of unprivileged user namespaces and limit unprivileged users' ability to configure netfilter rules. As a CISA KEV entry, federal agencies must remediate per BOD 22-01 by the catalog due date.

Affected
linux kernelv2.6.19-rc1 and later (all kernel branches prior to the fix; fixed versions not specified in source data)
netapp c400 firmware
netapp c250 firmware
netapp h410c firmware
netapp h300s firmware
netapp h500s firmware
netapp h700s firmware
netapp h410s firmware
netapp fas 8300 firmware
netapp fas 8700 firmware
netapp aff a400 firmware
brocade fabric operating system
Estimated exposure
massbillions of devices (Linux kernel runs on most servers, cloud instances, container hosts, Android devices and embedded systems) — The Linux kernel's installed base spans nearly all public cloud workloads, Linux servers, Android devices and embedded systems, and the flaw is also carried in NetApp and Brocade appliance firmware; note it is locally exploitable (AV:L),…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

CISA Known Exploited Vulnerability
Affected
Linux Kernel
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
netapplinuxbrocade
Products
c400 firmware, c250 firmware, h410c firmware, h300s firmware, h500s firmware, h700s firmware, h410s firmware, linux kernel, fabric operating system, fas 8300 firmware, fas 8700 firmware, aff a400 firmware
Weakness
CWE-787
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news