CRITICALExploited in the wildUnknown

Linux Kernel Heap Out-of-Bounds Write Vulnerability

https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=9fa492cdc160cd27ce1046cb36f47d3b2b1efa21 ; https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=b29c457a6511435960115c0f548c4360d5f4801d ; https://security.netapp.com/advisory/ntap-20210805-0010/ ; https://github.com/google/security-research/security/advisories/GHSA-xxx5-8mvq-3528 ; https://nvd.nist.gov/vuln/detail/CVE-2021-22555

CVE-2021-22555Published 10 months agoSource: CISA KEV

Affected packages

No package-level mapping for this advisory.

Exploit signal

Known exploited (CISA KEV)
Yes
EPSS score
78.68%
EPSS percentile
99.5%

EPSS is the probability a CVE is exploited in the wild; percentile is its rank among all CVEs. This advisory is in the top 100%.

Sources

No external sources available.

Recommended response stack

SnykScan your dependencies in CI and fix this vulnerability.SocketDetect malicious and compromised packages before they ship.

Some links are affiliate links — HackTribune may earn a commission at no extra cost to you.

Get incidents like this as alerts for your stack.

Join the beta
Linux Kernel Heap Out-of-Bounds Write Vulnerability | HackTribune