Netfilter x_tables Heap OOB Write Privilege Escalation
Title source: metasploitDescription
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
Exploits (18)
nomisec
WORKING POC
37 stars
by veritas501 · local
https://github.com/veritas501/CVE-2021-22555-PipeVersion
nomisec
WORKING POC
4 stars
by cgwalters · poc
https://github.com/cgwalters/container-cve-2021-22555
gitlab
by os-exploit · poc
https://gitlab.com/penetration-test-learn/10vuln/os-exploit/bcoles-kernel-exploits
metasploit
WORKING POC
GREAT
by Andy Nguyen (theflow@), Szymon Janusz, bcoles · rubypoclinux
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/linux/local/netfilter_xtables_heap_oob_write_priv_esc.rb
References (10)
Scores
CVSS v3
8.3
EPSS
0.8524
EPSS Percentile
99.4%
Attack Vector
ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Lab Environment
COMMUNITY
Community Lab
+11 more repos
Details
CISA KEV
2025-10-06
VulnCheck KEV
2024-03-18
ENISA EUVD
EUVD-2021-9696
CWE
CWE-787
Status
published
Products (21)
brocade/fabric_operating_system
linux/linux_kernel
2.6.19 - 4.4.267
netapp/aff_500f_firmware
netapp/aff_a250_firmware
netapp/aff_a400_firmware
netapp/c250_firmware
netapp/c400_firmware
netapp/cloud_backup
netapp/fas_8300_firmware
netapp/fas_8700_firmware
... and 11 more
Published
Jul 07, 2021
KEV Added
Oct 06, 2025
Tracked Since
Feb 18, 2026