Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 78.7%; technical severity is CVSS 7.8.
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
Who should care
- Teams operating Fabric Operating System, Kernel, Linux Kernel +19 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Fabric Operating System, Kernel, Linux Kernel +19 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Patch
- Git Kernel Security patch X Tables.cGit KernelVerification pending ↗
- Git Kernel Security patch X Tables.cGit KernelVerification pending ↗
- Exploit information from packetstormsecurity.comPacketstormsecurityVerification pending ↗
- Exploit information from packetstormsecurity.comPacketstormsecurityVerification pending ↗
- Exploit information from packetstormsecurity.comPacketstormsecurityVerification pending ↗
Technical details
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- CWE
- CWE-787
- Affected versions
- Brocade Fabric Operating System (Version -); Linux Kernel; Linux Linux Kernel (Start Including 2.6.19, End Excluding 4.4.267 | Start Including 4.5, End Excluding 4.9.267 | Start Including 4.10, End Excluding 4.14.231 | Start Including 4.15, End Excluding 4.19.188); Netapp Aff 500f Firmware (Version -); Netapp Aff A250 Firmware (Version -); Netapp Aff A400 Firmware (Version -); Netapp C250 Firmware (Version -); Netapp C400 Firmware (Version -)
- Fixed versions
- Linux Linux Kernel (Fixed from 4.4.267, 4.9.267, 4.14.231, 4.19.188, 5.4.113, 5.10.31, 5.12)
- Published
- 7 July 2021
- Attack vector
- Local
- Privileges required
- Low
- User interaction
- None
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 78.7%
- Signal calculated at 81