CVE-2021-22555 HIGH

CVE-2021-22555: Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE

Vendor N/A
Product Linux Kernel
Weakness CWE-787
KEV Status Known Exploited
Published July 7, 2021
Last update December 30, 2025

CVSS base score

8.3/10
Attack vector Adjacent
Attack complexity High
Privileges required None
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

CISA mandated remediation

02CISA Required Action

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Key dates

03Disclosure timeline

July 7, 2021 CVE published
December 30, 2025 Record updated

External resources

04References