Out-of-bounds Write Affecting kernel-debug-devel package, versions <0:3.10.0-1160.41.1.el7
Threat Intelligence
Exploit Maturity
Mature
EPSS
0.21% (60th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-CENTOS7-KERNELDEBUGDEVEL-2185812
- published 26 Jul 2021
- disclosed 7 Jul 2021
Introduced: 7 Jul 2021
CVE-2021-22555 Open this link in a new tabHow to fix?
Upgrade Centos:7
kernel-debug-devel
to version 0:3.10.0-1160.41.1.el7 or higher.
NVD Description
Note: Versions mentioned in the description apply only to the upstream kernel-debug-devel
package and not the kernel-debug-devel
package as distributed by Centos
.
See How to fix?
for Centos:7
relevant fixed versions and status.
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
References
- https://security.netapp.com/advisory/ntap-20210805-0010/
- https://access.redhat.com/security/cve/CVE-2021-22555
- http://packetstormsecurity.com/files/163528/Linux-Kernel-Netfilter-Heap-Out-Of-Bounds-Write.html
- http://packetstormsecurity.com/files/163878/Kernel-Live-Patch-Security-Notice-LSN-0080-1.html
- http://packetstormsecurity.com/files/164155/Kernel-Live-Patch-Security-Notice-LSN-0081-1.html
- http://packetstormsecurity.com/files/164437/Netfilter-x_tables-Heap-Out-Of-Bounds-Write-Privilege-Escalation.html
- https://github.com/google/security-research/security/advisories/GHSA-xxx5-8mvq-3528
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=9fa492cdc160cd27ce1046cb36f47d3b2b1efa21
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/net/netfilter/x_tables.c?id=b29c457a6511435960115c0f548c4360d5f4801d
- https://access.redhat.com/errata/RHSA-2021:3327
- http://packetstormsecurity.com/files/165477/Kernel-Live-Patch-Security-Notice-LSN-0083-1.html
- https://www.exploit-db.com/exploits/50135
CVSS Scores
version 3.1