BlackTreeCVE Intelligence
← Back to the CVE catalogue
Full vulnerability report · 2021
CVE-2021-22555High confidence

Linux Kernel Heap Out-of-Bounds Write Vulnerability

Linux · Kernel

Official source article: GitHub GHSA-XXX5-8MVQ-3528 ↗. Check the applicable product and release in the original source.

8.3HighCVSS 3.1
Recommended action
Patch only the product branches with a verified fix

CISA confirms exploitation in the wild and lists 2025-10-27 as the remediation due date. Verified remediation exists for at least one product or source, but 1 structured product or package state remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Fix availability varies by product
R
Operational reassessment

Published severity in operational context

Open reassessment dashboard →
Published severityHighOperational priority:Critical, raised one band.upgradedsince 6 Oct 2025

Evidence used

  • CISA confirms exploitation in the wild.
  • A structured source references public exploit or proof-of-concept material.
  • EPSS is 78.68% for the current model date.

Compensating controls

  • Validate the affected product branch and deploy the verified fixed release.
  • Restrict local access and enforce least privilege on affected hosts.
  • Increase monitoring for the attack path and post-exploitation behaviour described in the report.

Verification

  1. Confirm that the asset runs Linux Kernel and falls inside the recorded affected range.
  2. Verify the installed build against the product-specific fixed version after deployment.
  3. Validate exposure, authentication requirements and compensating controls in the actual environment.
  4. Reopen this reassessment when CVSS, KEV, EPSS, exploit evidence or remediation changes.
Mitigation target: Within 3 daysRemediation target: Within 90 days

This automated reassessment organises public evidence. It does not know asset exposure, business impact or control effectiveness and does not replace CVSS or a human risk decision.

Cross-source reconciliation

Remediation availability differs by product scope

Verified remediation exists for at least one product or source, but 1 structured product or package state remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Distribution package intelligence

Release-specific package status

Debian, ubuntu findings are scoped to the named distribution, release and source package. An absent finding does not mean a package is unaffected.

5 package states
Package result overrides the generic status

BlackTree has verified remediation for at least one product or source, but the relevant distribution still reports no fixed package for 1 affected package state shown here. Treat those rows as affected with no fix until that distribution publishes a fixed version.

Repository candidate not checked

A published vendor fix does not prove that a matching update is enabled and installable on a particular asset. Confirm the local package candidate before scheduling remediation.

Distribution releaseSource packageVendor stateFixed versionEvidence
Debian trixietrixie · sourcelinuxVendor fix publishedDebian records a fixed source-package version for this release.5.10.38-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian bookwormbookworm · sourcelinuxVendor fix publishedDebian records a fixed source-package version for this release.5.10.38-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian forkyforky · sourcelinuxVendor fix publishedDebian records a fixed source-package version for this release.5.10.38-1Debian Security Tracker ↗Source updated 6 Oct 2026
Debian sidsid · sourcelinuxVendor fix publishedDebian records a fixed source-package version for this release.5.10.38-1Debian Security Tracker ↗Source updated 6 Oct 2026
Ubuntu 24.04 LTSnoble · standard archivelinux-raspi-realtimeAffected, no fix publishedCanonical OVAL identifies this running kernel flavour as affected and does not publish a fixed package version in this definition.Not published in this feedCanonical Ubuntu Security ↗Source updated 5 Oct 2026
Optional official sources

National CERT insights
?CERT means Computer Emergency Response Team; CSIRT is the closely related term Computer Security Incident Response Team.

Choose official national sources for this report. Each advisory shows its original language. Your selection is remembered on this device and included in shared links.

Official European source

ENISA European Vulnerability Database

Official EUVD identifiers, advisory evidence and known-exploited context. Missing fields are not treated as evidence of low risk.

1 current
ENISA EUVD identifier

EUVD-2021-9696

CISA KEV mirrored by ENISA

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

EUVD state
Present in the current official mapping
Known exploitation
Recorded by ENISA since 6 Oct 2025. Evidence sources: cisa_kev.
ENISA score
8.3 · CVSS 3.1
Advisory evidence
48 linked advisory records
Explicit mitigation evidence

Only statements that explicitly mention a fix, patch, update, workaround or mitigation are shown here.

  • csaf_redhat · RHSA-2021:3044Red Hat Security Advisory: kpatch-patch security update
  • csaf_redhat · RHSA-2021:3477Red Hat Security Advisory: RHV-H security update (redhat-virtualization-host) 4.3.18
  • csaf_redhat · RHSA-2021:3327Red Hat Security Advisory: kernel security and bug fix update
  • csaf_opensuse · openSUSE-SU-2021:2427-1Security update for the Linux Kernel
  • csaf_suse · SUSE-SU-2021:2599-1Security update for the Linux Kernel
  • csaf_opensuse · openSUSE-SU-2021:1076-1Security update for the Linux Kernel
  • csaf_suse · SUSE-SU-2021:2409-1Security update for the Linux Kernel
  • csaf_redhat · RHSA-2021:3057Red Hat Security Advisory: kernel security, bug fix, and enhancement update
  • csaf_suse · SUSE-SU-2021:2427-1Security update for the Linux Kernel
  • csaf_redhat · RHSA-2021:3381Red Hat Security Advisory: kpatch-patch security update
  • csaf_suse · SUSE-SU-2021:2560-1Security update for the Linux Kernel (Live Patch 15 for SLE 15 SP1)
  • csaf_opensuse · openSUSE-SU-2021:2409-1Security update for the Linux Kernel
  • csaf_suse · SUSE-SU-2021:2416-1Security update for the Linux Kernel
  • csaf_suse · SUSE-SU-2021:2487-1Security update for the Linux Kernel (Live Patch 0 for SLE 15 SP3)
  • csaf_suse · SUSE-SU-2021:2438-1Security update for the Linux Kernel
  • csaf_redhat · RHSA-2021:3363Red Hat Security Advisory: kernel security, bug fix, and enhancement update
  • csaf_suse · SUSE-SU-2021:2415-1Security update for the Linux Kernel
  • csaf_redhat · RHSA-2021:3235Red Hat Security Advisory: Red Hat Virtualization Host security and bug fix update [ovirt-4.4.7]
  • csaf_redhat · RHSA-2021:3173Red Hat Security Advisory: kernel security update
  • csaf_suse · SUSE-SU-2021:2599-2Security update for the Linux Kernel
  • csaf_suse · SUSE-SU-2021:2451-1Security update for the Linux Kernel
  • csaf_redhat · RHSA-2021:3522Red Hat Security Advisory: kernel security and bug fix update
  • csaf_suse · SUSE-SU-2021:2422-1Security update for the Linux Kernel
  • csaf_redhat · RHSA-2021:3725Red Hat Security Advisory: kernel security and bug fix update
  • csaf_suse · SUSE-SU-2021:2559-1Security update for the Linux Kernel (Live Patch 2 for SLE 15 SP3)
  • csaf_redhat · RHSA-2021:3812Red Hat Security Advisory: kernel security update
  • csaf_redhat · RHSA-2021:3399Red Hat Security Advisory: kernel security and bug fix update
  • csaf_redhat · RHSA-2021:3088Red Hat Security Advisory: kernel-rt security and bug fix update
  • csaf_redhat · RHSA-2021:3814Red Hat Security Advisory: kpatch-patch security update
  • csaf_opensuse · openSUSE-SU-2021:2415-1Security update for the Linux Kernel
  • csaf_suse · SUSE-SU-2021:2538-1Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3)
  • csaf_redhat · RHSA-2021:3375Red Hat Security Advisory: kernel-rt security and bug fix update
  • csaf_suse · SUSE-SU-2021:2408-1Security update for the Linux Kernel
  • csaf_redhat · RHSA-2025:17733Red Hat Security Advisory: kernel security update
  • csaf_suse · SUSE-SU-2021:2584-1Security update for the Linux Kernel (Live Patch 19 for SLE 15 SP1)
  • csaf_suse · SUSE-SU-2021:2542-1Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP2)
  • csaf_redhat · RHSA-2021:3380Red Hat Security Advisory: kpatch-patch security update
  • csaf_suse · SUSE-SU-2021:2407-1Security update for the Linux Kernel
  • csaf_suse · SUSE-SU-2021:2406-1Security update for the Linux Kernel
  • csaf_suse · SUSE-SU-2021:2421-1Security update for the Linux Kernel
  • csaf_redhat · RHSA-2021:3523Red Hat Security Advisory: kpatch-patch security update
  • csaf_redhat · RHSA-2021:3181Red Hat Security Advisory: kpatch-patch security update
  • csaf_redhat · RHSA-2021:3328Red Hat Security Advisory: kernel-rt security and bug fix update
  • csaf_redhat · RHSA-2021:3321Red Hat Security Advisory: kernel security and bug fix update
  • csaf_suse · SUSE-SU-2021:2577-1Security update for the Linux Kernel (Live Patch 15 for SLE 15 SP2)
  • csaf_suse · SUSE-SU-2021:2643-1Security update for the Linux Kernel
Recommended actionPatch only the product branches with a verified fix

CISA confirms exploitation in the wild and lists 2025-10-27 as the remediation due date. Verified remediation exists for at least one product or source, but 1 structured product or package state remain unresolved. Apply remediation only to the exact product branch confirmed by its source.

Fix availability varies by product
01

What, why and how

Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.

What

Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.

Why

A bounds error lets data be written beyond the intended memory region, potentially corrupting control data.

How

An attacker operating through an adjacent network may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

What

Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.

Why

A bounds error lets data be written beyond the intended memory region, potentially corrupting control data.

How

An attacker operating through an adjacent network may attempt exploitation without authentication or user interaction. If successful, the issue may cause the confidentiality, integrity or availability impact described by the vendor.

02

Exploit reality and attack path

CVSS severity, EPSS forecast probability, public exploit material and CISA-confirmed exploitation are separate signals.

Observed exploitation
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Confirmed in the wild

CISA added this CVE to its Known Exploited Vulnerabilities catalogue on 2025-10-06.

Public PoC / exploit material
?Confirmed exploitation and public exploit material are separate signals. Attacks can occur without public proof-of-concept or exploit code.
Reference recorded

A structured CVE source labels at least one public reference as exploit material. BlackTree has not independently validated that it is safe, reliable or weaponised.

Likely attack path
an adjacent network → Out-of-bounds Write → cause the confidentiality, integrity or availability impact described by the vendor
Attack surface
Adjacent
Privileges required
None: unauthenticated exploitation is possible
User interaction
None
Attack complexity
High: exploitation depends on specific conditions
Security boundary
Changed: exploitation can affect a different security authority
Weakness
?CWE means Common Weakness Enumeration: a standard category for the underlying weakness.
CWE-787 ↗

CWE-787: Out-of-bounds Write. The product writes data past the end, or before the beginning, of the intended buffer.

CVSS vector
?CVSS means Common Vulnerability Scoring System. The vector records the metric values used to calculate technical severity.
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Common Vulnerability Scoring System 3.1: the compact vector below is decoded into plain language.

AVAdjacentAttack vector: The attacker must be on an adjacent or logically close network.ACHighAttack complexity: Successful exploitation depends on specific conditions outside the attacker's direct control.PRNonePrivileges required: The attacker does not need an account or existing privileges.UINoneUser interaction: No action by another user is required.SChangedScope: The attack can affect a component governed by a different security authority.CHighConfidentiality impact: A successful attack can cause a major loss.IHighIntegrity impact: A successful attack can cause a major loss.AHighAvailability impact: A successful attack can cause a major loss.
Post-exploitation / living off the land
No specific living-off-the-land technique is confirmed in the structured sources. Monitor normal administration tools for activity inconsistent with the affected service's baseline.
UnauthenticatedCWE-787CISA KEVPublic exploit reference
A

Official authority intelligence

Only matched European and national findings are included. Language selectors and unavailable sources are omitted.

ENISA EUVD · EUVD-2021-9696Known-exploited evidence recorded

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

Official EUVD record ↗
BSI · German · WID-SEC-2026-2442Oracle JD Edwards: Mehrere Schwachstellen

Ein entfernter, anonymer oder authentisierter Angreifer kann mehrere Schwachstellen in Oracle JD Edwards ausnutzen, um die Vertraulichkeit, Integrität und Verfügbarkeit zu gefährden.

Official advisory ↗
BSI · German · WID-SEC-2023-0063Juniper Junos Space: Mehrere Schwachstellen

Ein Angreifer aus dem angrenzenden Netzwerk oder ein entfernter anonymer, authentisierter oder lokaler Angreifer kann mehrere Schwachstellen in Juniper Junos Space ausnutzen, um Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, einen Denial-of-Service-Zustand auszulösen, beliebigen Code auszuführen und seine Privilegien zu erweitern.

Official advisory ↗
BSI · German · WID-SEC-2025-0227IBM QRadar SIEM: Mehrere Schwachstellen

Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in IBM QRadar SIEM ausnutzen, um seine Privilegien zu erweitern, Administratorrechte zu erlangen, beliebigen Programmcode auszuführen, Informationen offenzulegen, Dateien zu manipulieren oder Sicherheitsvorkehrungen zu umgehen.

Official advisory ↗
BSI · German · WID-SEC-2022-0609Linux Kernel: Schwachstelle ermöglicht Erlangen von Systemrechten

Ein lokaler Angreifer kann eine Schwachstelle im Linux Kernel ausnutzen, um Systemrechte zu erlangen und einen Denial of Service Zustand herzustellen.

Official advisory ↗
Cyber Security Agency of Singapore · English · CSA-SB-20210714Security Bulletin 14 Jul 2021

The Cyber Security Agency of Singapore included this CVE in its official Security Bulletin 14 Jul 2021, published on 14 July 2021. Open the linked bulletin for the product, severity and reference information published in that issue.

Official advisory ↗
CERT-FR · French · CERTFR-2025-AVI-0893Multiples vulnérabilités dans le noyau Linux de Red Hat

97 du 13 octobre 2025 https://access.redhat.com/errata/RHSA-2025:17797 Bulletin de sécurité Red Hat RHSA-2025:17812 du 13 octobre 2025 https://access.redhat.com/errata/RHSA-2025:17812 Bulletin de sécurité Red Hat RHSA-2025:17958 du 14 octobre 2025 https://access.redhat.com/errata/RHSA-2025:17958 Bulletin de sécurité Red Hat RHSA-2025:18043 du 15 octobre 2025 https://access.redhat.com/errata/RHSA-2025:18043 Bulletin de sécurité Red Hat RHSA-2025:18054 du 15 octobre 2025 https://access.redhat.com/errata/RHSA-2025:18054 Bulletin de sécurité Red Hat RHSA-2025:18098 du 15 octobre 2025 https://access.redhat.com/errata/RHSA-2025:18098 Référence CVE CVE-2021-22555 https://www.cve.org/CVERecord?id=CVE-2021-22555 Référence CVE CVE-2022-49969 https://www.cve.org/CVERecord?id=CVE-2022-49969 Référence CVE CVE-2022-49985 https://www.cve.org/CVERecord?id=CVE-2022-49985 Référence CVE CVE-2022-50087 https://www.cve.org/CVERecord?id=CVE-2022-50087 Référence CVE CVE-2022-50228 https://www.cve.org/CVERecord?id=CVE-2022-50228 Référence CVE CVE-2022-50229 https://www.cve.org/CVERecord?id=CVE-2022-50229 Référence CVE CVE-2023-53125 https://www.cve.org/CVERecord?id=CVE-2023-53125 Référence CVE CVE-2023-53186 https://www.cve.org/CVERecord?id=CVE-2023-53186 Référence CVE CVE-2023-53305 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2023-AVI-0051Multiples vulnérabilités dans les produits Juniper

ve.org/CVERecord?id=CVE-2021-2171 Référence CVE CVE-2021-2174 https://www.cve.org/CVERecord?id=CVE-2021-2174 Référence CVE CVE-2021-2178 https://www.cve.org/CVERecord?id=CVE-2021-2178 Référence CVE CVE-2021-2179 https://www.cve.org/CVERecord?id=CVE-2021-2179 Référence CVE CVE-2021-2180 https://www.cve.org/CVERecord?id=CVE-2021-2180 Référence CVE CVE-2021-2194 https://www.cve.org/CVERecord?id=CVE-2021-2194 Référence CVE CVE-2021-2202 https://www.cve.org/CVERecord?id=CVE-2021-2202 Référence CVE CVE-2021-2226 https://www.cve.org/CVERecord?id=CVE-2021-2226 Référence CVE CVE-2021-22543 https://www.cve.org/CVERecord?id=CVE-2021-22543 Référence CVE CVE-2021-22555 https://www.cve.org/CVERecord?id=CVE-2021-22555 Référence CVE CVE-2021-23017 https://www.cve.org/CVERecord?id=CVE-2021-23017 Référence CVE CVE-2021-2307 https://www.cve.org/CVERecord?id=CVE-2021-2307 Référence CVE CVE-2021-2341 https://www.cve.org/CVERecord?id=CVE-2021-2341 Référence CVE CVE-2021-2342 https://www.cve.org/CVERecord?id=CVE-2021-2342 Référence CVE CVE-2021-2369 https://www.cve.org/CVERecord?id=CVE-2021-2369 Référence CVE CVE-2021-2372 https://www.cve.org/CVERecord?id=CVE-2021-2372 Référence CVE CVE-2021-23840 https://www.cve.org/CVERecord?id=CVE-2021-23840 Référence CVE CVE-2021-23841 https://www.cve.org/CVERecord?id=CVE-2021-2

Official advisory ↗
CERT-FR · French · CERTFR-2022-AVI-916Multiples vulnérabilités dans les produits Juniper

CVERecord?id=CVE-2020-28469 Référence CVE CVE-2020-29661 https://www.cve.org/CVERecord?id=CVE-2020-29661 Référence CVE CVE-2020-7053 https://www.cve.org/CVERecord?id=CVE-2020-7053 Référence CVE CVE-2020-8648 https://www.cve.org/CVERecord?id=CVE-2020-8648 Référence CVE CVE-2021-0543 https://www.cve.org/CVERecord?id=CVE-2021-0543 Référence CVE CVE-2021-0920 https://www.cve.org/CVERecord?id=CVE-2021-0920 Référence CVE CVE-2021-20265 https://www.cve.org/CVERecord?id=CVE-2021-20265 Référence CVE CVE-2021-20271 https://www.cve.org/CVERecord?id=CVE-2021-20271 Référence CVE CVE-2021-22543 https://www.cve.org/CVERecord?id=CVE-2021-22543 Référence CVE CVE-2021-22555 https://www.cve.org/CVERecord?id=CVE-2021-22555 Référence CVE CVE-2021-23840 https://www.cve.org/CVERecord?id=CVE-2021-23840 Référence CVE CVE-2021-25220 https://www.cve.org/CVERecord?id=CVE-2021-25220 Référence CVE CVE-2021-27363 https://www.cve.org/CVERecord?id=CVE-2021-27363 Référence CVE CVE-2021-27364 https://www.cve.org/CVERecord?id=CVE-2021-27364 Référence CVE CVE-2021-27365 https://www.cve.org/CVERecord?id=CVE-2021-27365 Référence CVE CVE-2021-28165 https://www.cve.org/CVERecord?id=CVE-2021-28165 Référence CVE CVE-2021-29154 https://www.cve.org/CVERecord?id=CVE-2021-29154 Référence CVE CVE-2021-29650 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-912Multiples vulnérabilités dans IBM Qradar

.org/CVERecord?id=CVE-2019-3857 Référence CVE CVE-2019-3863 https://www.cve.org/CVERecord?id=CVE-2019-3863 Référence CVE CVE-2019-9636 https://www.cve.org/CVERecord?id=CVE-2019-9636 Référence CVE CVE-2019-9924 https://www.cve.org/CVERecord?id=CVE-2019-9924 Référence CVE CVE-2020-13954 https://www.cve.org/CVERecord?id=CVE-2020-13954 Référence CVE CVE-2020-1971 https://www.cve.org/CVERecord?id=CVE-2020-1971 Référence CVE CVE-2020-27777 https://www.cve.org/CVERecord?id=CVE-2020-27777 Référence CVE CVE-2020-7226 https://www.cve.org/CVERecord?id=CVE-2020-7226 Référence CVE CVE-2020-9492 https://www.cve.org/CVERecord?id=CVE-2020-9492 Référence CVE CVE-2021-22555 https://www.cve.org/CVERecord?id=CVE-2021-22555 Référence CVE CVE-2021-22696 https://www.cve.org/CVERecord?id=CVE-2021-22696 Référence CVE CVE-2021-27219 https://www.cve.org/CVERecord?id=CVE-2021-27219 Référence CVE CVE-2021-28163 https://www.cve.org/CVERecord?id=CVE-2021-28163 Référence CVE CVE-2021-28165 https://www.cve.org/CVERecord?id=CVE-2021-28165 Référence CVE CVE-2021-28169 https://www.cve.org/CVERecord?id=CVE-2021-28169 Référence CVE CVE-2021-29154 https://www.cve.org/CVERecord?id=CVE-2021-29154 Référence CVE CVE-2021-29425 https://www.cve.org/CVERecord?id=CVE-2021-29425 Référence CVE CVE-2021-29650 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-791Multiples vulnérabilités dans les produits IBM

/CVERecord?id=CVE-2021-1817 Référence CVE CVE-2021-1820 https://www.cve.org/CVERecord?id=CVE-2021-1820 Référence CVE CVE-2021-1825 https://www.cve.org/CVERecord?id=CVE-2021-1825 Référence CVE CVE-2021-1826 https://www.cve.org/CVERecord?id=CVE-2021-1826 Référence CVE CVE-2021-20271 https://www.cve.org/CVERecord?id=CVE-2021-20271 Référence CVE CVE-2021-20305 https://www.cve.org/CVERecord?id=CVE-2021-20305 Référence CVE CVE-2021-20578 https://www.cve.org/CVERecord?id=CVE-2021-20578 Référence CVE CVE-2021-2163 https://www.cve.org/CVERecord?id=CVE-2021-2163 Référence CVE CVE-2021-22543 https://www.cve.org/CVERecord?id=CVE-2021-22543 Référence CVE CVE-2021-22555 https://www.cve.org/CVERecord?id=CVE-2021-22555 Référence CVE CVE-2021-22918 https://www.cve.org/CVERecord?id=CVE-2021-22918 Référence CVE CVE-2021-23336 https://www.cve.org/CVERecord?id=CVE-2021-23336 Référence CVE CVE-2021-23337 https://www.cve.org/CVERecord?id=CVE-2021-23337 Référence CVE CVE-2021-23362 https://www.cve.org/CVERecord?id=CVE-2021-23362 Référence CVE CVE-2021-23364 https://www.cve.org/CVERecord?id=CVE-2021-23364 Référence CVE CVE-2021-2341 https://www.cve.org/CVERecord?id=CVE-2021-2341 Référence CVE CVE-2021-2369 https://www.cve.org/CVERecord?id=CVE-2021-2369 Référence CVE CVE-2021-2388 https://www.cve.org/CVERecord?id=CVE-2

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-786Multiples vulnérabilités dans le noyau Linux de Red Hat

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service, un contournement de la politique de sécurité et une atteinte à l'intégrité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-752Multiples vulnérabilités dans le noyau Linux de Red Hat

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Elles permettent à un attaquant de provoquer une atteinte à l'intégrité des données, une atteinte à la confidentialité des données et une élévation de privilèges.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-720Multiples vulnérabilités dans le noyau Linux de RedHat

De multiples vulnérabilités ont été découvertes dans le noyau Linux de RedHat. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-699Multiples vulnérabilités dans le noyau Linux d'Ubuntu

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service et une atteinte à l'intégrité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-680Multiples vulnérabilités dans le noyau Linux de Red Hat

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service à distance, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-665Multiples vulnérabilités dans le noyau Linux de Red Hat

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Elles permettent à un attaquant de provoquer un déni de service, une atteinte à l'intégrité des données et une élévation de privilèges.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-640Multiples vulnérabilités dans le noyau Linux de Red Hat

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Elles permettent à un attaquant de provoquer un déni de service et une élévation de privilèges.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-635Multiples vulnérabilités dans le noyau Linux d'Ubuntu

De multiples vulnérabilités ont été découvertes dans le noyau Linux d'Ubuntu. Elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-628Vulnérabilité dans le noyau Linux d'Ubuntu

Une vulnérabilité a été découverte dans le noyau Linux d'Ubuntu. Elle permet à un attaquant de provoquer une exécution de code arbitraire et un déni de service.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-612Multiples vulnérabilités dans le noyau Linux de SUSE

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, un déni de service et un contournement de la politique de sécurité.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-611Multiples vulnérabilités dans le noyau Linux de Red Hat

De multiples vulnérabilités ont été découvertes dans le noyau Linux de Red Hat. Elles permettent à un attaquant de provoquer un déni de service et une élévation de privilèges.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-602Multiples vulnérabilités dans le noyau Linux de SUSE

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-595Multiples vulnérabilités dans le noyau Linux de SUSE

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-584Multiples vulnérabilités dans le noyau Linux de SUSE

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire, un déni de service et une atteinte à l'intégrité des données.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-585Multiples vulnérabilités dans le noyau Linux de SUSE

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Elles permettent à un attaquant de provoquer un déni de service et une élévation de privilèges.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-581Multiples vulnérabilités dans le noyau Linux de SUSE

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur, un déni de service et une élévation de privilèges.

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-570Multiples vulnérabilités dans le noyau Linux de SUSE

ERecord?id=CVE-2020-26141 Référence CVE CVE-2020-26145 https://www.cve.org/CVERecord?id=CVE-2020-26145 Référence CVE CVE-2020-26147 https://www.cve.org/CVERecord?id=CVE-2020-26147 Référence CVE CVE-2020-26558 https://www.cve.org/CVERecord?id=CVE-2020-26558 Référence CVE CVE-2020-36385 https://www.cve.org/CVERecord?id=CVE-2020-36385 Référence CVE CVE-2020-36386 https://www.cve.org/CVERecord?id=CVE-2020-36386 Référence CVE CVE-2021-0129 https://www.cve.org/CVERecord?id=CVE-2021-0129 Référence CVE CVE-2021-0512 https://www.cve.org/CVERecord?id=CVE-2021-0512 Référence CVE CVE-2021-0605 https://www.cve.org/CVERecord?id=CVE-2021-0605 Référence CVE CVE-2021-22555 https://www.cve.org/CVERecord?id=CVE-2021-22555 Référence CVE CVE-2021-23133 https://www.cve.org/CVERecord?id=CVE-2021-23133 Référence CVE CVE-2021-23134 https://www.cve.org/CVERecord?id=CVE-2021-23134 Référence CVE CVE-2021-32399 https://www.cve.org/CVERecord?id=CVE-2021-32399 Référence CVE CVE-2021-33034 https://www.cve.org/CVERecord?id=CVE-2021-33034 Référence CVE CVE-2021-33909 https://www.cve.org/CVERecord?id=CVE-2021-33909 Référence CVE CVE-2021-34693 https://www.cve.org/CVERecord?id=CVE-2021-34693 Référence CVE CVE-2021-3609 https://www.cve.org/CVERecord?id=CVE-2021-3609 Gestion détaillée du document le 23 juillet 2021 Version initial

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-563Multiples vulnérabilités dans le noyau Linux de SUSE

ERecord?id=CVE-2020-26141 Référence CVE CVE-2020-26145 https://www.cve.org/CVERecord?id=CVE-2020-26145 Référence CVE CVE-2020-26147 https://www.cve.org/CVERecord?id=CVE-2020-26147 Référence CVE CVE-2020-26558 https://www.cve.org/CVERecord?id=CVE-2020-26558 Référence CVE CVE-2020-36385 https://www.cve.org/CVERecord?id=CVE-2020-36385 Référence CVE CVE-2020-36386 https://www.cve.org/CVERecord?id=CVE-2020-36386 Référence CVE CVE-2021-0129 https://www.cve.org/CVERecord?id=CVE-2021-0129 Référence CVE CVE-2021-0512 https://www.cve.org/CVERecord?id=CVE-2021-0512 Référence CVE CVE-2021-0605 https://www.cve.org/CVERecord?id=CVE-2021-0605 Référence CVE CVE-2021-22555 https://www.cve.org/CVERecord?id=CVE-2021-22555 Référence CVE CVE-2021-23133 https://www.cve.org/CVERecord?id=CVE-2021-23133 Référence CVE CVE-2021-23134 https://www.cve.org/CVERecord?id=CVE-2021-23134 Référence CVE CVE-2021-32399 https://www.cve.org/CVERecord?id=CVE-2021-32399 Référence CVE CVE-2021-33034 https://www.cve.org/CVERecord?id=CVE-2021-33034 Référence CVE CVE-2021-33200 https://www.cve.org/CVERecord?id=CVE-2021-33200 Référence CVE CVE-2021-33624 https://www.cve.org/CVERecord?id=CVE-2021-33624 Référence CVE CVE-2021-33909 https://www.cve.org/CVERecord?id=CVE-2021-33909 Référence CVE CVE-2021-34693 https://www.cve.org/CVERecord?id=

Official advisory ↗
CERT-FR · French · CERTFR-2021-AVI-550Multiples vulnérabilités dans le noyau Linux de SUSE

De multiples vulnérabilités ont été découvertes dans le noyau Linux de SUSE. Certaines d'entre elles permettent à un attaquant de provoquer un déni de service, une atteinte à l'intégrité des données et une atteinte à la confidentialité des données.

Official advisory ↗
JVN iPedia · Japanese · JVNDB-2021-008982Linux Kernel における境界外書き込みに関する脆弱性

Linux Kernel には、境界外書き込みに関する脆弱性が存在します。

Official advisory ↗
KISA KrCERT/CC · Korean · KNVD-6596美 CISA 발표 주요 Exploit 정보공유(Update. 2025-10-06)

Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space.

Official advisory ↗
03

Patch and workaround

Operational remediation based on structured source evidence.

Status
?Patch availability is based on structured fixed-version fields and authoritative update references. If no fix is verified, check the vendor advisory before making a change.
Fix availability varies by product
Affected
Linux kernel: 2.6.19-rc1 < unspecified
Fixed
An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
Action
Use the product-specific evidence above. Patch only products with a verified fixed release, and keep every affected or under-investigation state without a matching fix in the remediation queue.
Workaround
No verified workaround is recorded. Limit untrusted access and use least privilege until authoritative guidance is available.
04

Evidence and provenance

Published 7 Jul 2021 · Last source change 30 Dec 2025, 20:32 UTC · CWE-787 · Out-of-bounds Write

CVE recordCVE.org · 5.2
CVSS sourceCNA
EPSS source
?The date BlackTree first stored a score for this CVE from the daily FIRST EPSS feed.
FIRST · tracked since 2026-08-14
European sourceENISA EUVD · EUVD-2021-9696
Product sourceCISA KEV
Remediation sourceCVE/CNA references
CWE sourceCNA
NVD statusNVD enriched

Core structured fields are present and their contributing authorities are shown above.

Material change intelligence

What changed after publication

View recent updates ↗
  1. Affected versionsThe structured affected or fixed version information changed.
    Before
    2.6.19-rc1 < unspecified · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    After
    Linux Kernel: 2.6.19-rc1 < unspecified · Fixed: An authoritative update reference is available, but the fixed version is not recorded in the structured CVE fields. Check the linked vendor advisory for the applicable release.
    CNA ↗
Material fields only · duplicate refreshes suppressed · history retained for the configured operational retention period
Technical terms and abbreviations used in this report
CVE
Common Vulnerabilities and Exposures: the public identifier for one disclosed vulnerability.
CVSS
Common Vulnerability Scoring System: a technical severity framework; it is not patching priority by itself.
EPSS
Exploit Prediction Scoring System: FIRST's estimate of the probability that exploitation activity will be observed in the next 30 days; it is a forecast, not confirmation.
CWE
Common Weakness Enumeration: the standard category describing the underlying software or hardware weakness.
CNA
CVE Numbering Authority: an organisation authorised to assign and publish CVE records.
CISA ADP
Cybersecurity and Infrastructure Security Agency Authorized Data Publisher: structured enrichment added to a CVE record.
NVD
National Vulnerability Database: NIST's enrichment service for CVE records.
CERT / CSIRT
A computer security incident response team that publishes warnings or coordinates incident response.
PoC
Proof of concept: public material that demonstrates or helps reproduce exploitation.
CSAF
Common Security Advisory Framework: a machine-readable format for security advisories.
LoTL
Living off the land: abuse of legitimate tools or system functions during an attack.
Free version - for non-commercial use only.CVE-2021-22555 · cve.blacktree.nl