peter bassill · operator
$ cve CVE-2021-22555 JSON

CVE-2021-22555 KEV EXPLOIT

8.3
HIGH · CVSS 3.1 · EPSS 78.7% (pctl 100)

Patch first

On CISA KEV — known exploited in the wild, due 2025-10-27.

Description

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

Scoring

CVSS8.3 (HIGH, v3.1)
VectorCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
EPSS78.68% — more likely to be exploited than 100% of all CVEs
WeaknessCWE-787
On CISA KEVyes — remediate by 2025-10-27
Public exploityes
Published2021-07-07
Last modified2026-06-17

CISA KEV

NameLinux Kernel Heap Out-of-Bounds Write Vulnerability
Added2025-10-06
Due2025-10-27
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (36)

VendorProduct
brocadefabric operating system
linuxlinux kernel
netappaff 500f
netappaff 500f firmware
netappaff a250
netappaff a250 firmware
netappaff a400
netappaff a400 firmware
netappc250
netappc250 firmware
netappc400
netappc400 firmware
netappcloud backup
netappfas 8300
netappfas 8300 firmware
netappfas 8700
netappfas 8700 firmware
netapph300s
netapph300s firmware
netapph410c
netapph410c firmware
netapph410s
netapph410s firmware
netapph500s
netapph500s firmware
netapph610c
netapph610c firmware
netapph610s
netapph610s firmware
netapph615c
netapph615c firmware
netapph700s
netapph700s firmware
netapphci management node
netappsolidfire
netappsolidfire baseboard management controller

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD