Netfilter x_tables Heap OOB Write Privilege Escalation
Title source: metasploitExploitation Summary
CVE-2021-22555 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added October 6, 2025.
EIP tracks 16 public exploits from researchers including TheFloW, veritas501, xyjl-ly, including a Metasploit module exploits/linux/local/netfilter_xtables_heap_oob_write_priv_esc.
AI-analyzed exploit summary This exploit leverages an out-of-bounds write vulnerability in the Linux kernel's netfilter subsystem (CVE-2021-22555) to achieve local privilege escalation. It uses a combination of heap spraying, memory corruption, and SMAP/KASLR bypass techniques to gain root privileges.
Description
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
Exploits (16)
This exploit leverages an out-of-bounds write vulnerability in the Linux kernel's netfilter subsystem (CVE-2021-22555) to achieve local privilege escalation. It uses a combination of heap spraying, memory corruption, and SMAP/KASLR bypass techniques to gain root privileges.
This repository contains a functional exploit for CVE-2021-22555, leveraging a pipe-primitive technique to bypass KASLR, SMAP, SMEP, and KPTI. The exploit targets a memory corruption vulnerability in the Linux kernel, specifically manipulating message queues and pipe buffers to achieve local privilege escalation (LPE).
This repository contains a functional exploit for CVE-2021-22555, a heap out-of-bounds write vulnerability in the Linux kernel's netfilter subsystem. The exploit demonstrates privilege escalation by leveraging memory corruption, SMAP bypass, KASLR bypass, and ultimately executing arbitrary kernel code to gain root privileges.
This repository contains a functional exploit for CVE-2021-22555, a Linux kernel privilege escalation vulnerability. It includes a Dockerized exploit, a seccomp mitigation profile, and detailed documentation on the vulnerability and mitigation strategies.
This repository contains a functional Linux privilege escalation exploit for CVE-2021-22555, leveraging memory corruption in the Linux kernel to escalate privileges. The exploit demonstrates a multi-stage attack involving memory spraying, SMAP bypass, KASLR bypass, and kernel code execution to gain root access.
This repository contains a functional exploit for CVE-2021-22555, a heap overflow vulnerability in the Linux kernel's netfilter subsystem. The exploit leverages a heap out-of-bounds write to achieve privilege escalation to root on Ubuntu 20.04 with kernel 5.8.0-48-generic.
This repository contains a Python-based exploit for CVE-2021-22555, which automates the attack process including host discovery, port scanning, SSH brute-forcing, and exploit execution. The script leverages Metasploit's RPC interface to establish a shell session and deliver the exploit payload.
This repository contains a functional exploit for CVE-2021-22555, a Linux kernel vulnerability in the netfilter subsystem. The exploit demonstrates a local privilege escalation (LPE) by leveraging memory corruption, SMAP bypass, KASLR bypass, and ultimately achieving root privileges.
This repository contains a functional proof-of-concept exploit for CVE-2021-22555, a vulnerability in the Linux kernel's netfilter subsystem. The exploit triggers an out-of-bounds write in kmalloc-512 by manipulating ip6_tables structures via setsockopt, demonstrating the vulnerability in a controlled manner.
This repository contains a functional exploit for CVE-2021-22555, a Linux kernel vulnerability that allows local privilege escalation (LPE) via memory corruption in the netfilter subsystem. The exploit demonstrates a multi-stage attack involving heap spraying, SMAP/KASLR bypass, and ROP chain execution to gain root privileges.
This repository contains a functional exploit for CVE-2021-22555, a Linux kernel Netfilter local privilege escalation vulnerability. The exploit leverages memory corruption, SMAP bypass, KASLR bypass, and kernel code execution to escalate privileges to root.
This is a functional local privilege escalation exploit for CVE-2021-22555, targeting a memory corruption vulnerability in the Linux kernel's netfilter subsystem. The exploit uses a multi-stage approach involving message queue manipulation, heap spraying, and kernel address leakage to achieve arbitrary kernel code execution and root privileges.
This Metasploit module exploits a heap out-of-bounds write vulnerability in the Linux kernel's netfilter x_tables (CVE-2021-22555) to achieve local privilege escalation. It targets Ubuntu kernels and requires specific conditions, such as a minimum message queue size (MSGMNI).
References (10)
Scores
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H