Database/Kernel, userspace & hypervisor
Linux kernel (netfilter x_tables): Heap out-of-bounds write in xt_compat_target_from_user()
CVSS 7.8CVE-2021-22555Kernel, userspace & hypervisorKnown exploitedcurated
Impact
Heap out-of-bounds write in xt_compat_target_from_user(); reliable container escape via unprivileged userns + CAP_NET_ADMIN [KEV]
Who can reach it
Any tenant process in a container with a user namespace
What to do
Livepatchable; otherwise drain + reboot. Compensating control: disable unprivileged user namespaces (kernel.unprivileged_userns_clone=0) - breaks rootless Podman/Apptainer, which many HPC tenants rely on
References
Related entries
- sudo: Baron Samedit: heap overflow in sudo argument parsing, root from any local accountCVE-2021-3156 · sudoHigh
- Linux kernel (seq_file / fs layer): Sequoia: size_t-to-int conversion in the filesystem layer, local root on defaultCVE-2021-33909 · Linux kernel (seq_file / fs layer)High
- Linux kernel (eBPF verifier): eBPF ALU32 bitwise-op bounds tracking flawCVE-2021-3490 · Linux kernel (eBPF verifier)High
- polkit: Local privilege escalation via polkit_system_bus_name_get_creds_sync() raceCVE-2021-3560 · polkitHigh
- polkit (pkexec): PwnKit: local privilege escalation to root via argv handlingCVE-2021-4034 · polkit (pkexec)High
- Linux kernel (net/smc): The CDC send-completion handler takes a lock inside an smc_sock that close() has already freedCVE-2021-46925 · Linux kernel (net/smc)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.