CVE-2021-22555
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
19Exploited in Wild
-Decision
Descriptions
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
En el archivo net/netfilter/x_tables.c se ha detectado una escritura fuera de límites en la pila que afecta a Linux desde la versión 2.6.19-rc1. Esto permite a un atacante alcanzar privilegios o causar una denegación de servicio (por medio de corrupción de la memoria de la pila) mediante el espacio de nombres de usuario
A flaw was discovered in processing setsockopt IPT_SO_SET_REPLACE (or IP6T_SO_SET_REPLACE) for 32 bit processes on 64 bit systems. This flaw will allow local user to gain privileges or cause a DoS through user name space. This action is usually restricted to root-privileged users but can also be leveraged if the kernel is compiled with CONFIG_USER_NS and CONFIG_NET_NS and the user is granted elevated privileges.
Maxim Levitsky discovered that the KVM hypervisor implementation for AMD processors in the Linux kernel did not properly prevent a guest VM from enabling AVIC in nested guest VMs. An attacker in a guest VM could use this to write to portions of the host’s physical memory. Maxim Levitsky and Paolo Bonzini discovered that the KVM hypervisor implementation for AMD processors in the Linux kernel allowed a guest VM to disable restrictions on VMLOAD/VMSAVE in a nested guest. An attacker in a guest VM could use this to read or write portions of the host's physical memory. Various other vulnerabilities were also addressed.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-01-05 CVE Reserved
- 2021-07-07 CVE Published
- 2021-07-15 First Exploit
- 2024-09-16 CVE Updated
- 2025-03-18 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-787: Out-of-bounds Write
CAPEC
References (28)
URL | Date | SRC |
---|---|---|
https://access.redhat.com/security/cve/CVE-2021-22555 | 2021-10-12 | |
https://bugzilla.redhat.com/show_bug.cgi?id=1980101 | 2021-10-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Netapp Search vendor "Netapp" | Fas 8300 Firmware Search vendor "Netapp" for product "Fas 8300 Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | Fas 8300 Search vendor "Netapp" for product "Fas 8300" | - | - |
Safe
|
Netapp Search vendor "Netapp" | Fas 8700 Firmware Search vendor "Netapp" for product "Fas 8700 Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | Fas 8700 Search vendor "Netapp" for product "Fas 8700" | - | - |
Safe
|
Netapp Search vendor "Netapp" | Aff A400 Firmware Search vendor "Netapp" for product "Aff A400 Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | Aff A400 Search vendor "Netapp" for product "Aff A400" | - | - |
Safe
|
Netapp Search vendor "Netapp" | Aff A250 Firmware Search vendor "Netapp" for product "Aff A250 Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | Aff A250 Search vendor "Netapp" for product "Aff A250" | - | - |
Safe
|
Netapp Search vendor "Netapp" | Aff 500f Firmware Search vendor "Netapp" for product "Aff 500f Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | Aff 500f Search vendor "Netapp" for product "Aff 500f" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H610c Firmware Search vendor "Netapp" for product "H610c Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H610c Search vendor "Netapp" for product "H610c" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H610s Firmware Search vendor "Netapp" for product "H610s Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H610s Search vendor "Netapp" for product "H610s" | - | - |
Safe
|
Netapp Search vendor "Netapp" | H615c Firmware Search vendor "Netapp" for product "H615c Firmware" | - | - |
Affected
| in | Netapp Search vendor "Netapp" | H615c Search vendor "Netapp" for product "H615c" | - | - |
Safe
|
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 2.6.19 < 4.4.267 Search vendor "Linux" for product "Linux Kernel" and version " >= 2.6.19 < 4.4.267" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.5 < 4.9.267 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.5 < 4.9.267" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.10 < 4.14.231 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.10 < 4.14.231" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.15 < 4.19.188 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.15 < 4.19.188" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.20 < 5.4.113 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.20 < 5.4.113" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.5 < 5.10.31 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.5 < 5.10.31" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 5.11 < 5.12 Search vendor "Linux" for product "Linux Kernel" and version " >= 5.11 < 5.12" | - |
Affected
| ||||||
Brocade Search vendor "Brocade" | Fabric Operating System Search vendor "Brocade" for product "Fabric Operating System" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Hci Management Node Search vendor "Netapp" for product "Hci Management Node" | - | - |
Affected
| ||||||
Netapp Search vendor "Netapp" | Solidfire Search vendor "Netapp" for product "Solidfire" | - | - |
Affected
|