CVE-2021-22555
KEVHIGH 8.3EPSS 78.7%
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v3.1
- 8.3 HIGH
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H - CVSS v2.0
- 4.6 MEDIUM
AV:L/AC:L/Au:N/C:P/I:P/A:P - EPSS
- 78.68% chance of exploitation in the next 30 days, 100th percentile
- CISA KEV
- added 2025-10-06
- Published
- 2021-07-07
- Updated
- 2025-12-30
Proof-of-concept exploits (26)
- http://packetstormsecurity.com/files/163878/Kernel-Live-Patch-Security-Notice-LSN-0080-1.…
- http://packetstormsecurity.com/files/164155/Kernel-Live-Patch-Security-Notice-LSN-0081-1.…
- http://packetstormsecurity.com/files/164437/Netfilter-x_tables-Heap-Out-Of-Bounds-Write-P…
- http://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.…
- google/security-research/security/advisories/GHSA-xxx5-8mvq-3528
- 1nzag/CVE-2022-09951★ · 2024-01-03
- AndreevSemen/CVE-2022-09951★ · 2023-03-10
- Bonfee/CVE-2022-0995497★ · 2022-03-27
- ChoKyuWon/exploit_articles2★ · 2021-07-30
- JoneyJunior/cve-2021-225551★ · 2021-07-15
- PIG-007/kernelAll28★ · 2022-06-14
- YunDingLab/struct_sanitizer33★ · 2021-09-23
- cgwalters/container-cve-2021-225554★ · 2021-07-19
- daletoniris/CVE-2021-22555-esc-priv1★ · 2021-10-01
- hardenedvault/vault_range_poc47★ · 2025-04-05
- letsr00t/-2021-LOCALROOT-CVE-2021-225550★ · 2024-02-05
- letsr00t/CVE-2021-225550★ · 2024-02-27
- masjohncook/netsec-project1★ · 2023-05-26
- pashayogi/CVE-2021-225550★ · 2023-08-20
- ssst0n3/ctrsploit_archived6★ · 2021-07-30
- tukru/CVE-2021-225553★ · 2023-09-07
- veritas501/CVE-2021-22555-PipeVersion40★ · 2022-05-18
- xyjl-ly/CVE-2021-22555-Exploit14★ · 2022-07-28
- Spydomain/CVE-2021-22555-Poc
- WhatsWrongAndWhy/CVE-2021-22555
- glutton-su/CVE-2021-22555