CISA KEV · catalog date Oct 6, 2025 · first observed Jul 19, 2026
Evidence dossier
CVE-2021-22555
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
Exploited in the wild (CISA KEV since Oct 6, 2025). NVD reports CVSS 3.1 7.8. EPSS estimates 78.7% exploit likelihood as of Aug 26, 2026.
As of Aug 27, 2026
Normalized restatement
A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space
- State
- PUBLISHED
- Published
- Jul 7, 2021
- Updated
- Dec 30, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAGoogleOriginal evidence ↗
Record text: Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
Inspect raw assertion
- Field
container- Value
- Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Linux Kernel Heap Out-of-Bounds Write Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Heap Out-of-Bounds Write Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 78.68% probability · 99.56th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.786840000000; percentile 0.995550000000
FIRST EPSS · score date Aug 26, 2026 · 99.6th percentile · first observed Aug 26, 2026
NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
Inspect raw assertion
- Field
container- Value
- Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
Linux Kernel Heap Out-of-Bounds Write Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Heap Out-of-Bounds Write Vulnerability
78.68% probability · 99.56th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.786840000000; percentile 0.995550000000
Applicability
Cited product scope
Grouped from 33 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
37 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "2.6.19-rc1", "lessThan": "unspecified", "versionType": "custom"}]product-23aeada3235973f117e1ef01828de0481d4fb220e18831034dafbba652224021Linked exactInspect raw assertion
cpe:2.3:o:brocade:fabric_operating_system:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 8 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
41cd1160-b681-41ef-9eb4-06ce0f53c501
product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9Linked exactInspect raw assertions
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 2.6.19; through excluding 4.4.267
- Match ID
3e869a37-b25a-4cfd-afa1-964c540b7283
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 4
- Logic
- OR
- Version bounds
- from including 4.20; through excluding 5.4.113
- Match ID
bb3ce52d-3245-4b6c-9c92-897bcb496882
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 4.10; through excluding 4.14.231
- Match ID
c1285cf4-6285-4288-9981-03a04f93519e
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 4.5; through excluding 4.9.267
- Match ID
8f1c60cb-5594-496c-8df0-68d909707254
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 6
- Logic
- OR
- Version bounds
- from including 5.11; through excluding 5.12
- Match ID
66c052db-c48a-43d4-a1a8-af1e331199d4
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 4.15; through excluding 4.19.188
- Match ID
46073f63-74d1-4675-999a-574c1c13b627
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 7 · node/0 · match 5
- Logic
- OR
- Version bounds
- from including 5.5; through excluding 5.10.31
- Match ID
eb0a42d4-2dac-4de0-a20b-a2700aa5e63a
product-7b8986ee9ae08eaac96e9eb48b6af27d9329dbce8a241be69a60b319b86425d9Linked exactInspect raw assertion
cpe:2.3:h:netapp:aff_500f:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 13 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2ab58180-e5e0-4056-abf9-a99e9f6a9e86
product-87e29177776562b7c2d17b31130f7555479ee7d9f9d26ac073f3d02703d989c5Linked exactInspect raw assertion
cpe:2.3:o:netapp:aff_500f_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 13 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
578bb9a7-bf28-4068-a9a6-1de19ceec293
product-8d1fa26a7a1d4306ab4fa944a9f4a407d4687dd3e0f86398181f30261fe4a1beLinked exactInspect raw assertion
cpe:2.3:h:netapp:aff_a250:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 12 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d4b1f59c-6ada-4930-834f-2a8a8444f6ae
product-da44f088dbdab4a52924e45f9b8bf875a9e35587b0993d452c2d4685a847b898Linked exactInspect raw assertion
cpe:2.3:o:netapp:aff_a250_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 12 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0d5de972-f8b8-4964-943a-da0bd18289d1
product-29e1491c2ff949ad3e52a8717a8863b71759e1b18bdc29add51d73f5de69ae64Linked exactInspect raw assertion
cpe:2.3:h:netapp:aff_a400:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 11 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f3e70a56-dba8-45c7-8c49-1a036501156f
product-28e630a4349a538364f2a71f6ca71b146ac10e1516d3b82221c432b2f0935df0Linked exactInspect raw assertion
cpe:2.3:o:netapp:aff_a400_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 11 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
56fd9b9a-bbe5-4ca5-b9f9-b16e1fe738c8
product-81eb33109c31a4237933ba812ce110b56b71ff0f4d92452756a4ce64c4b6284dLinked exactInspect raw assertion
cpe:2.3:h:netapp:c250:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 1 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
58de2b52-4e49-4cd0-9310-00291b0352c7
product-22c964a2123b48ccc0f33f04f9ff63daf5adc2214000936708b0cc671be0d39bLinked exactInspect raw assertion
cpe:2.3:o:netapp:c250_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
f1ab1ec2-2560-494a-a51b-6f20ce318feb
product-550139cc27fcef7ba1a8092ed8e0597a7939e52ff1fc96f65d51bb311e46faa7Linked exactInspect raw assertion
cpe:2.3:h:netapp:c400:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 0 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ad443748-b0d1-4c1a-a62e-bd5fb5967370
product-656b98475b5116ffca73cfa0270f61023660a70cceba0dd9443fafdfb26af12bLinked exactInspect raw assertion
cpe:2.3:o:netapp:c400_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9ac7ad92-8b33-4137-a4ec-08641e4af857
product-82c0ed89ab714a80f8d7ca4b0a7a5e6e1968a59a16c17a9f6a2a0a6a4757f6bfLinked exactInspect raw assertion
cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 17 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
5c2089ee-5d7f-47ec-8ea5-0f69790564c4
product-8dc934c45d773690945fee4a05dba654cf2eb85dce617667b1bdab296ef9520aLinked exactInspect raw assertion
cpe:2.3:h:netapp:fas_8300:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 9 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e64576de-90f0-4f5e-9c82-ab745cfedbb7
product-745feafd01ad96841f96a2ec5122ae5ec11a145e44503c478c0ab91ab265ea1fLinked exactInspect raw assertion
cpe:2.3:o:netapp:fas_8300_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 9 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d5cdadab-72a5-4526-8432-e6c9ac56b29f
product-d4783839c9685743860d9377774dbbe5d8bf77e4d5a70126659962a5f6703345Linked exactInspect raw assertion
cpe:2.3:h:netapp:fas_8700:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 10 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6415e28a-4eac-4f7f-bd81-1a55ce8b6f40
product-43d5fc17316bbeaacfaa65ff87c6876fab7aebbec10f80ac2ae86db40adafddcLinked exactInspect raw assertion
cpe:2.3:o:netapp:fas_8700_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 10 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
ef5afe69-7990-4f80-9e63-d8ad58aa3a2d
product-5b787f6fb0dbffca7d5383cfa87cd93654a14ed60ccdd59abc2ba697fe7ead69Linked exactInspect raw assertion
cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 3 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
9f9c8c20-42eb-4ab5-bd97-212deb070c43
product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419Linked exactInspect raw assertion
cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 3 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
6770b6c3-732e-4e22-bf1c-2d2fd610061c
product-19a4460172d592ee30b338581dced13baf393eedf54989f7303c0971a7aa6832Linked exactInspect raw assertion
cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 2 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
cddf61b7-ec5c-467c-b710-b89f502cd04f
product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045aLinked exactInspect raw assertion
cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 2 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
234defe0-5ce5-4b0a-96b8-5d227cb8ed31
product-ae7668c0a5adbc5d6599144484fb84400193fe6c73d0e6bb570cd2a233e63b35Linked exactInspect raw assertion
cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 6 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8497a4c9-8474-4a62-8331-3fe862ed4098
product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481aeLinked exactInspect raw assertion
cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d0b4ad8a-f172-4558-aec6-ff424ba2d912
product-4c7f1f62606e18f71887f5954346c3f8c8376e418a089dca8282922aa180aff3Linked exactInspect raw assertion
cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Environmental constraint
- Configuration
- 4 · node/1 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e63d8b0f-006e-4801-bf9d-1c001bbfb4f9
Affected-product evidence
Accepted scope and product mapping
21 canonical links · 1 source-reported links
vendor-9c702362a97e8770255c53f324861f65f3209d35ce95f01842c69a458450f6fa · product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 7
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
53c5e949-6805-4ff3-92c9-2bd335a014d2699b8fe9-1465-47ed-a0ea-a2a3b2e23efd8a11adeb-2aa0-45ab-ab99-2959f12c559397399c70-ac63-4e4e-a779-15afa9a6f1639fb03d28-40e0-4ea9-a461-289b0b362b75b66e3711-cbdb-4b44-a186-9e7109246fa0ef7af3e5-c9b5-4b99-9919-0d2545868158vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-22c964a2123b48ccc0f33f04f9ff63daf5adc2214000936708b0cc671be0d39b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
2a3ce0e0-0eb9-4def-b948-697ab0086a6avendor-a13cabd890e634787181832fc87c21d5abcf42c0423d5b4ed08a561c09b128ee · product-23aeada3235973f117e1ef01828de0481d4fb220e18831034dafbba652224021
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d0779dcb-d87b-45de-bd5f-e543334486e6vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-28e630a4349a538364f2a71f6ca71b146ac10e1516d3b82221c432b2f0935df0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e5d8473f-22c2-47c5-ae07-295848a2b99fvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6d
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
07392d62-4b55-4d12-baa8-81d7dcd60005vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
97380d3c-b7e4-4d33-873b-3ca58385f9b5vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3f0c13ae987268d938a748a6775a56a1c59c577b908d80ca86854083f202c4a8
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6fd30691-96a0-4d00-bcd4-b7eee4d6b356vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-43d5fc17316bbeaacfaa65ff87c6876fab7aebbec10f80ac2ae86db40adafddc
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7f1e5f3f-f739-4c83-8111-bf6ebd40d55avendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-656b98475b5116ffca73cfa0270f61023660a70cceba0dd9443fafdfb26af12b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9f77d78f-e404-4a9a-b6b4-8b5e9c955af9vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-6b9f0b72c1309966cd256d7a215b9cab906dcc64be1cb9f934c338c91e098620
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
74e37009-a519-44d9-8577-ecbc260f1564vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-745feafd01ad96841f96a2ec5122ae5ec11a145e44503c478c0ab91ab265ea1f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
caec21aa-4dc6-4acb-b44f-072fac0ebf6bvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-82c0ed89ab714a80f8d7ca4b0a7a5e6e1968a59a16c17a9f6a2a0a6a4757f6bf
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
db047978-346f-4036-9f16-48d9e46da6a6vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-87e29177776562b7c2d17b31130f7555479ee7d9f9d26ac073f3d02703d989c5
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4ac19992-a24e-48cf-a0f9-bf1646f52ff6vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-b96bd9c5f25fe809238d4145773458d6ff936886a379c046bfbe8070415bf846
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
258a0d1f-e0b5-45b7-9936-8459e3239973vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5f812773-7344-4ad4-ae01-49cfb85bec02vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481ae
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
3d047073-0b2e-42e5-a642-58ddf433c2acvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-ca781182502f30abba72205d9867148c0b7d38157be8f19331a6471eb3d41e5e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
e49d5d09-59b0-4fb2-9925-0a131df123ecvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-ce5a951956802b54eda64165939e5e2c5df7ce5a73bad036b8ea9a7eb7fd5eed
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fda3ea2d-53e9-43fa-a72b-892f702ccdf9vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-da44f088dbdab4a52924e45f9b8bf875a9e35587b0993d452c2d4685a847b898
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9c84821b-f449-4649-a111-784fc9b15c7fvendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-dfafd2470f609ac33603458a6c7c24476cc0c1177151909fcc171d29415ce924
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4f204e9f-cf63-448f-9735-0b6f4afbd412vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
5955c59e-a3f9-4b72-b56e-50b52deb0a6cCanonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
a5df0844-4b46-4158-92f4-221a090dc275Assessments
CVSS by origin
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HAV:L/AC:L/Au:N/C:P/I:P/A:PCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:HDirect CVE/CNA normalized decisions
CVSS 3.1 · Primary · Original assertion · rank 1
CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H- Validation
- Valid match
- Recomputed
- 8.3
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.