Evidence dossier

CVE-2021-22555

Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE

Exploited in the wild (CISA KEV since Oct 6, 2025). NVD reports CVSS 3.1 7.8. EPSS estimates 78.7% exploit likelihood as of Aug 26, 2026.

86.287.9Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

A heap out-of-bounds write affecting Linux since v2.6.19-rc1 was discovered in net/netfilter/x_tables.c. This allows an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space

State
PUBLISHED
Published
Jul 7, 2021
Updated
Dec 30, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    Google

    Record text: Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE

    Inspect raw assertion
    Field
    container
    Value
    Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Linux Kernel Heap Out-of-Bounds Write Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Linux Kernel Heap Out-of-Bounds Write Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 78.68% probability · 99.56th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.786840000000; percentile 0.995550000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date Oct 6, 2025 · first observed Jul 19, 2026

Exploit likelihood78.68%

FIRST EPSS · score date Aug 26, 2026 · 99.6th percentile · first observed Aug 26, 2026

SeverityCVSS 7.8

NVD · CVSS 3.1 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
GoogleOriginal assertion
Record text

Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE

Inspect raw assertion
Field
container
Value
Heap Out-Of-Bounds Write in Netfilter IP6T_SO_SET_REPLACE
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Linux Kernel Heap Out-of-Bounds Write Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Linux Kernel Heap Out-of-Bounds Write Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

78.68% probability · 99.56th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.786840000000; percentile 0.995550000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
42Underlying assertions
36Canonical products
27Target assertions
15Constraint assertions

Grouped from 33 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

37 scope groups

Google · source assertedn/aLinux KernelDirect source scope
Affected: 2.6.19-rc1 to before unspecified (custom comparison)
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "2.6.19-rc1", "lessThan": "unspecified", "versionType": "custom"}]
NVD CPE · OPERATING SYSTEMbrocadefabric_operating_systemVulnerable target · 1 assertions
Version not applicableCanonical identity product-23aeada3235973f117e1ef01828de0481d4fb220e18831034dafbba652224021Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:brocade:fabric_operating_system:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    8 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    41cd1160-b681-41ef-9eb4-06ce0f53c501
NVD CPE · OPERATING SYSTEMlinuxlinux_kernelVulnerable target · 7 assertions
Any version (unconstrained) (>= 2.6.19, < 4.4.267); Any version (unconstrained) (>= 4.10, < 4.14.231); Any version (unconstrained) (>= 4.15, < 4.19.188); Any version (unconstrained) (>= 4.20, < 5.4.113); Any version (unconstrained) (>= 4.5, < 4.9.267); Any version (unconstrained) (>= 5.11, < 5.12); Any version (unconstrained) (>= 5.5, < 5.10.31)Canonical identity product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 2.6.19; through excluding 4.4.267
    Match ID
    3e869a37-b25a-4cfd-afa1-964c540b7283
  2. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 4.20; through excluding 5.4.113
    Match ID
    bb3ce52d-3245-4b6c-9c92-897bcb496882
  3. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 4.10; through excluding 4.14.231
    Match ID
    c1285cf4-6285-4288-9981-03a04f93519e
  4. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 4.5; through excluding 4.9.267
    Match ID
    8f1c60cb-5594-496c-8df0-68d909707254
  5. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 6
    Logic
    OR
    Version bounds
    from including 5.11; through excluding 5.12
    Match ID
    66c052db-c48a-43d4-a1a8-af1e331199d4
  6. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 4.15; through excluding 4.19.188
    Match ID
    46073f63-74d1-4675-999a-574c1c13b627
  7. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    7 · node/0 · match 5
    Logic
    OR
    Version bounds
    from including 5.5; through excluding 5.10.31
    Match ID
    eb0a42d4-2dac-4de0-a20b-a2700aa5e63a
NVD CPE · HARDWAREnetappaff_500fEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-7b8986ee9ae08eaac96e9eb48b6af27d9329dbce8a241be69a60b319b86425d9Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:aff_500f:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    13 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2ab58180-e5e0-4056-abf9-a99e9f6a9e86
NVD CPE · OPERATING SYSTEMnetappaff_500f_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-87e29177776562b7c2d17b31130f7555479ee7d9f9d26ac073f3d02703d989c5Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:aff_500f_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    13 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    578bb9a7-bf28-4068-a9a6-1de19ceec293
NVD CPE · HARDWAREnetappaff_a250Environmental constraint · 1 assertions
Version not applicableCanonical identity product-8d1fa26a7a1d4306ab4fa944a9f4a407d4687dd3e0f86398181f30261fe4a1beLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:aff_a250:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    12 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d4b1f59c-6ada-4930-834f-2a8a8444f6ae
NVD CPE · OPERATING SYSTEMnetappaff_a250_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-da44f088dbdab4a52924e45f9b8bf875a9e35587b0993d452c2d4685a847b898Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:aff_a250_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    12 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0d5de972-f8b8-4964-943a-da0bd18289d1
NVD CPE · HARDWAREnetappaff_a400Environmental constraint · 1 assertions
Version not applicableCanonical identity product-29e1491c2ff949ad3e52a8717a8863b71759e1b18bdc29add51d73f5de69ae64Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:aff_a400:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    11 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f3e70a56-dba8-45c7-8c49-1a036501156f
NVD CPE · OPERATING SYSTEMnetappaff_a400_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-28e630a4349a538364f2a71f6ca71b146ac10e1516d3b82221c432b2f0935df0Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:aff_a400_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    11 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    56fd9b9a-bbe5-4ca5-b9f9-b16e1fe738c8
NVD CPE · HARDWAREnetappc250Environmental constraint · 1 assertions
Version not applicableCanonical identity product-81eb33109c31a4237933ba812ce110b56b71ff0f4d92452756a4ce64c4b6284dLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:c250:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    1 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    58de2b52-4e49-4cd0-9310-00291b0352c7
NVD CPE · OPERATING SYSTEMnetappc250_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-22c964a2123b48ccc0f33f04f9ff63daf5adc2214000936708b0cc671be0d39bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:c250_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    f1ab1ec2-2560-494a-a51b-6f20ce318feb
NVD CPE · HARDWAREnetappc400Environmental constraint · 1 assertions
Version not applicableCanonical identity product-550139cc27fcef7ba1a8092ed8e0597a7939e52ff1fc96f65d51bb311e46faa7Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:c400:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    0 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ad443748-b0d1-4c1a-a62e-bd5fb5967370
NVD CPE · OPERATING SYSTEMnetappc400_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-656b98475b5116ffca73cfa0270f61023660a70cceba0dd9443fafdfb26af12bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:c400_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9ac7ad92-8b33-4137-a4ec-08641e4af857
NVD CPE · APPLICATIONnetappcloud_backupVulnerable target · 1 assertions
Version not applicableCanonical identity product-82c0ed89ab714a80f8d7ca4b0a7a5e6e1968a59a16c17a9f6a2a0a6a4757f6bfLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:netapp:cloud_backup:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    17 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    5c2089ee-5d7f-47ec-8ea5-0f69790564c4
NVD CPE · HARDWAREnetappfas_8300Environmental constraint · 1 assertions
Version not applicableCanonical identity product-8dc934c45d773690945fee4a05dba654cf2eb85dce617667b1bdab296ef9520aLinked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:fas_8300:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    9 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e64576de-90f0-4f5e-9c82-ab745cfedbb7
NVD CPE · OPERATING SYSTEMnetappfas_8300_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-745feafd01ad96841f96a2ec5122ae5ec11a145e44503c478c0ab91ab265ea1fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:fas_8300_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    9 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d5cdadab-72a5-4526-8432-e6c9ac56b29f
NVD CPE · HARDWAREnetappfas_8700Environmental constraint · 1 assertions
Version not applicableCanonical identity product-d4783839c9685743860d9377774dbbe5d8bf77e4d5a70126659962a5f6703345Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:fas_8700:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    10 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6415e28a-4eac-4f7f-bd81-1a55ce8b6f40
NVD CPE · OPERATING SYSTEMnetappfas_8700_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-43d5fc17316bbeaacfaa65ff87c6876fab7aebbec10f80ac2ae86db40adafddcLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:fas_8700_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    10 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    ef5afe69-7990-4f80-9e63-d8ad58aa3a2d
NVD CPE · HARDWAREnetapph300sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-5b787f6fb0dbffca7d5383cfa87cd93654a14ed60ccdd59abc2ba697fe7ead69Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:h300s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    3 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    9f9c8c20-42eb-4ab5-bd97-212deb070c43
NVD CPE · OPERATING SYSTEMnetapph300s_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:h300s_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    3 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    6770b6c3-732e-4e22-bf1c-2d2fd610061c
NVD CPE · HARDWAREnetapph410cEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-19a4460172d592ee30b338581dced13baf393eedf54989f7303c0971a7aa6832Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:h410c:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    2 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    cddf61b7-ec5c-467c-b710-b89f502cd04f
NVD CPE · OPERATING SYSTEMnetapph410c_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045aLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:h410c_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    2 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    234defe0-5ce5-4b0a-96b8-5d227cb8ed31
NVD CPE · HARDWAREnetapph410sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-ae7668c0a5adbc5d6599144484fb84400193fe6c73d0e6bb570cd2a233e63b35Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:h410s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    6 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8497a4c9-8474-4a62-8331-3fe862ed4098
NVD CPE · OPERATING SYSTEMnetapph410s_firmwareVulnerable target · 1 assertions
Version not applicableCanonical identity product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481aeLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:netapp:h410s_firmware:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d0b4ad8a-f172-4558-aec6-ff424ba2d912
NVD CPE · HARDWAREnetapph500sEnvironmental constraint · 1 assertions
Version not applicableCanonical identity product-4c7f1f62606e18f71887f5954346c3f8c8376e418a089dca8282922aa180aff3Linked exact
Scope constrained
Inspect raw assertion
  1. cpe:2.3:h:netapp:h500s:-:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Environmental constraint
    Configuration
    4 · node/1 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e63d8b0f-006e-4801-bf9d-1c001bbfb4f9

Affected-product evidence

Accepted scope and product mapping

21 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-9c702362a97e8770255c53f324861f65f3209d35ce95f01842c69a458450f6fa · product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9

Source class
Nvd cpe vulnerable target
Assertions
7
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
53c5e949-6805-4ff3-92c9-2bd335a014d2699b8fe9-1465-47ed-a0ea-a2a3b2e23efd8a11adeb-2aa0-45ab-ab99-2959f12c559397399c70-ac63-4e4e-a779-15afa9a6f1639fb03d28-40e0-4ea9-a461-289b0b362b75b66e3711-cbdb-4b44-a186-9e7109246fa0ef7af3e5-c9b5-4b99-9919-0d2545868158
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-22c964a2123b48ccc0f33f04f9ff63daf5adc2214000936708b0cc671be0d39b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
2a3ce0e0-0eb9-4def-b948-697ab0086a6a
Mapping establishedEvidence supported

vendor-a13cabd890e634787181832fc87c21d5abcf42c0423d5b4ed08a561c09b128ee · product-23aeada3235973f117e1ef01828de0481d4fb220e18831034dafbba652224021

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d0779dcb-d87b-45de-bd5f-e543334486e6
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-28e630a4349a538364f2a71f6ca71b146ac10e1516d3b82221c432b2f0935df0

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e5d8473f-22c2-47c5-ae07-295848a2b99f
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3953d9e2b43fe76a6f94d197de1c80572cc133eca41cf7c6f838a4d8f875fb6d

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
07392d62-4b55-4d12-baa8-81d7dcd60005
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3d0915e39b5cbd4a35c4f9144f57e38484db6d2fffb6f1d595f5fd6eb6a7045a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
97380d3c-b7e4-4d33-873b-3ca58385f9b5
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-3f0c13ae987268d938a748a6775a56a1c59c577b908d80ca86854083f202c4a8

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6fd30691-96a0-4d00-bcd4-b7eee4d6b356
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-43d5fc17316bbeaacfaa65ff87c6876fab7aebbec10f80ac2ae86db40adafddc

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7f1e5f3f-f739-4c83-8111-bf6ebd40d55a
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-656b98475b5116ffca73cfa0270f61023660a70cceba0dd9443fafdfb26af12b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9f77d78f-e404-4a9a-b6b4-8b5e9c955af9
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-6b9f0b72c1309966cd256d7a215b9cab906dcc64be1cb9f934c338c91e098620

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
74e37009-a519-44d9-8577-ecbc260f1564
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-745feafd01ad96841f96a2ec5122ae5ec11a145e44503c478c0ab91ab265ea1f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
caec21aa-4dc6-4acb-b44f-072fac0ebf6b
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-82c0ed89ab714a80f8d7ca4b0a7a5e6e1968a59a16c17a9f6a2a0a6a4757f6bf

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
db047978-346f-4036-9f16-48d9e46da6a6
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-87e29177776562b7c2d17b31130f7555479ee7d9f9d26ac073f3d02703d989c5

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4ac19992-a24e-48cf-a0f9-bf1646f52ff6
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-b96bd9c5f25fe809238d4145773458d6ff936886a379c046bfbe8070415bf846

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
258a0d1f-e0b5-45b7-9936-8459e3239973
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-b9e7a301eef0306dd174904e39d76a7c24000b372471d8c7805d9a00b6a6e419

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5f812773-7344-4ad4-ae01-49cfb85bec02
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-c29ed97377ecd5a1bb977b857e33722917ef8494748bf83825ca6748f85481ae

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
3d047073-0b2e-42e5-a642-58ddf433c2ac
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-ca781182502f30abba72205d9867148c0b7d38157be8f19331a6471eb3d41e5e

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
e49d5d09-59b0-4fb2-9925-0a131df123ec
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-ce5a951956802b54eda64165939e5e2c5df7ce5a73bad036b8ea9a7eb7fd5eed

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
fda3ea2d-53e9-43fa-a72b-892f702ccdf9
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-da44f088dbdab4a52924e45f9b8bf875a9e35587b0993d452c2d4685a847b898

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9c84821b-f449-4649-a111-784fc9b15c7f
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-dfafd2470f609ac33603458a6c7c24476cc0c1177151909fcc171d29415ce924

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4f204e9f-cf63-448f-9735-0b6f4afbd412
Mapping establishedEvidence supported

vendor-d1dcf2e2192106a1eb34744930a80b83005fa5d60195c923256e69ac39974aed · product-f13a7dff7633e8a34e5465fdbeace2aa7562b47a38b49f4f05dc5e2406bc9c6a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
5955c59e-a3f9-4b72-b56e-50b52deb0a6c
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
a5df0844-4b46-4158-92f4-221a090dc275

Assessments

CVSS by origin

7.8
NVDCVSS 3.1 · role Primary · priority eligiblevalid_matchCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
4.6
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:L/AC:L/Au:N/C:P/I:P/A:P
8.3
cve-coordination@google.comCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
8.3
GoogleCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

Direct CVE/CNA normalized decisions

8.3Priority eligible

Google

CVSS 3.1 · Primary · Original assertion · rank 1

CVSS:3.1/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
Validation
Valid match
Recomputed
8.3
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.