CVE-2021-22555
Linux Kernel vulnerability analysis and mitigation

Overview

A heap out-of-bounds write vulnerability (CVE-2021-22555) was discovered in the Linux kernel's netfilter subsystem, specifically in net/netfilter/xtables.c. The vulnerability has existed since Linux version 2.6.19-rc1 and affects the processing of setsockopt IPTSOSETREPLACE (or IP6TSOSET_REPLACE) for 32-bit processes on 64-bit systems (CVE, NVD).

Technical details

The vulnerability occurs in the xtcompattargetfromuser() function where the allocation size for converting 32-bit to 64-bit structures is not properly calculated. When IPTSOSETREPLACE or IP6TSOSETREPLACE is called in compat mode, the target->targetsize is not taken into account for the allocation size, leading to an out-of-bounds write. The issue allows writing up to 4 bytes of zeros past the allocated buffer boundary (GitHub Advisory).

Impact

The vulnerability allows local users to gain privileges or cause a denial of service through heap memory corruption when exploited through user namespace. The severity is rated as HIGH with a CVSS score of 7.8 (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), potentially leading to disclosure of sensitive information, modification of data, or system crashes (NetApp Advisory).

Mitigation and workarounds

The vulnerability was fixed in Linux kernel version 5.12 with commit b29c457a6511435960115c0f548c4360d5f4801d, and backported to stable versions 5.10.31, 5.4.113, 4.19.188, 4.14.231, 4.9.267, and 4.4.267. Users should update their Linux kernel to these patched versions or later (GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Linux Kernel vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-39998N/AN/A
  • Linux KernelLinux Kernel
  • kernel-ipaclones-internal
NoNoOct 15, 2025
CVE-2025-39997N/AN/A
  • Linux KernelLinux Kernel
  • kernel-debug-core
NoNoOct 15, 2025
CVE-2025-39996N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-core
NoNoOct 15, 2025
CVE-2025-39965N/AN/A
  • Linux KernelLinux Kernel
  • kernel-rt-debug-modules-core
NoNoOct 13, 2025
CVE-2025-39964N/AN/A
  • Linux KernelLinux Kernel
  • kernel-uki-virt
NoYesOct 13, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management