VDB
HOTFIX-SA-2021%3A0012
HOTFIX-SA-2021%3A0012
PUBLISHED
CVSS 7.800000190734863 HIGH
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. The compat IPT_SO_SET_REPLACE/IP6T_SO_SET_REPLACE setsockopt implementation in the netfilter subsystem in the Linux kernel allows local users to gain privileges or cause a denial of service (heap memory corruption) via user namespace. This vulnerability is very similar to CVE-2016-3134 (CVSSv3 8.4 High) and CVE-2016-4997 (CVSSv3 7.8 High).
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Alibaba Cloud | kernel-hotfix-5928799-24.al7 |
Exploit Intelligence
- CVE-2021-22555 Exploit (github-poc-repo)
- Script of Network Security Project - Attack on CVE-2021-22555 (github-poc-repo)
- Linux Kernel 2.6.19 < 5.9 - 'Netfilter Local Privilege Escalation' (github-poc-repo)
- This repo hosts TUKRU's Linux Privilege Escalation exploit (CVE-2021-22555). It demonstrates gaining root privileges via a vulnerability. Tested on Ubuntu 5.8.0-48-generic and COS 5.4.89+. Use responsibly and ethically. (github-poc-repo)
- letsr00t/-2021-LOCALROOT-CVE-2021-22555 (github-poc-repo)
- letsr00t/CVE-2021-22555 (github-poc-repo)
- Spydomain/CVE-2021-22555-Poc (github-poc-repo)
- glutton-su/CVE-2021-22555 (github-poc-repo)
- glutton-su/CVE-2021-22555 (github-poc)
- Spydomain/CVE-2021-22555-Poc (github-poc)
…and 13 more exploits
Timeline
- Jul 21, 2021 CVE Published
- Jul 21, 2021 CVE Updated