Skip to content

CVE-2021-22555

Out-of-bounds Write — is CVE-2021-22555real, exploitable, or a false positive? Here's the community ground truth.

High · CVSS 8.3EPSS 78.7%CISA KEVCWE-787 · Out-of-bounds Write

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

Published

Embed this verdict
TruePositive verdict for CVE-2021-22555
Markdown
[![TruePositive verdict](https://www.truepositive.app/cve/CVE-2021-22555/badge.svg)](https://www.truepositive.app/cve/CVE-2021-22555)
HTML
<a href="https://www.truepositive.app/cve/CVE-2021-22555"><img src="https://www.truepositive.app/cve/CVE-2021-22555/badge.svg" alt="TruePositive verdict for CVE-2021-22555"></a>

Live badge — updates automatically as the community verdict changes.

Community ground truth

Community verdict

3 verdicts
Not a real issue

Includes TruePositive's curated baseline from public sources — community verdicts accrue on top.

to add your verdict.

Community real-world severity: High (High 3) — CVSS base score 8.3

In line with its CVSS base score.

Field notes & remediation

Verdicts are the quick signal — notes are the evidence and fixes behind them.

  • 0
    Field note · Priya NairCurated

    Confirmed exploited in the wild — listed in the CISA KEV catalog (added 2025-10-06). Treat as real and prioritize patching over triage.

Same weaknessCWE-787 · Out-of-bounds Write.