CVE-2021-22555
KEV PoC ×5massLinux Kernel Netfilter Heap OOB Write Enables Privilege Escalation (CVE-2021-22555)
CISA: Linux Kernel Heap Out-of-Bounds Write Vulnerability
CVE-2021-22555 is a heap out-of-bounds write (CWE-787) in the netfilter x_tables code (net/netfilter/x_tables.c) of the Linux kernel, a flaw present since version v2.6.19-rc1. A local attacker can trigger the heap memory corruption through user namespaces, meaning even unprivileged users, such as workloads running inside containers, can reach the vulnerable code path. Successful exploitation lets the attacker gain elevated kernel-level privileges, typically fully escaping a container, or crash the system in a denial of service. Affected users are essentially any Linux deployment on kernels in the affected range (distributions, cloud servers, container hosts), and CISA's product mapping additionally covers NetApp firmware for its c400/c250, H300S/H410S/H410C/H500S/H700S, FAS 8300/8700 and AFF A400 systems plus Brocade Fabric OS. The flaw has public proof-of-concept exploits (including Google security research), a high 78.7% EPSS exploitation probability over 30 days, and CISA added it to the Known Exploited Vulnerabilities catalog on 2025-10-06, confirming exploitation in the wild.
What to do: Upgrade Linux kernels to patched versions from your distribution and apply vendor live patches where offered (Ubuntu Kernel Live Patch notices LSN-0080/0081/0083 are referenced in public advisories), and install the corresponding NetApp and Brocade firmware updates for the listed systems. Where patching must wait, restrict creation of unprivileged user namespaces and limit unprivileged users' ability to configure netfilter rules. As a CISA KEV entry, federal agencies must remediate per BOD 22-01 by the catalog due date.
| linux kernel | v2.6.19-rc1 and later (all kernel branches prior to the fix; fixed versions not specified in source data) |
| netapp c400 firmware | — |
| netapp c250 firmware | — |
| netapp h410c firmware | — |
| netapp h300s firmware | — |
| netapp h500s firmware | — |
| netapp h700s firmware | — |
| netapp h410s firmware | — |
| netapp fas 8300 firmware | — |
| netapp fas 8700 firmware | — |
| netapp aff a400 firmware | — |
| brocade fabric operating system | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
- Affected
- Linux Kernel
- Required action
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- netapplinuxbrocade
- Products
- c400 firmware, c250 firmware, h410c firmware, h300s firmware, h500s firmware, h700s firmware, h410s firmware, linux kernel, fabric operating system, fas 8300 firmware, fas 8700 firmware, aff a400 firmware
- Weakness
- CWE-787
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H