Database/Kernel, userspace & hypervisor
Linux kernel (netfilter x_tables): Heap out-of-bounds write in xt_compat_target_from_user()
CVE-2021-22555Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Heap out-of-bounds write in xt_compat_target_from_user(); reliable container escape via unprivileged userns + CAP_NET_ADMIN [KEV]
Who can reach it
Any tenant process in a container with a user namespace
What to do
Livepatchable; otherwise drain + reboot. Compensating control: disable unprivileged user namespaces (kernel.unprivileged_userns_clone=0) - breaks rootless Podman/Apptainer, which many HPC tenants rely on
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.