---
id: CVE-2021-45485
title: >-
  In the IPv6 implementation in the Linux kernel before 5.13.3,
  net/ipv6/output_core.c has an information leak because of certain use of a
  hash table which, although big, doesn't properly consider that IPv6-based
  attackers can typically ch…
summary: >-
  In the IPv6 implementation in the Linux kernel before 5.13.3,
  net/ipv6/output_core.c has an information leak because of certain use of a
  hash table which, although big, doesn't properly consider that IPv6-based
  attackers can typically ch…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-327
vendor: netapp
product: e-series_santricity_os_controller
affected:
  - linux_kernel < 4.4.276
  - 'linux_kernel >= 4.5, < 4.9.276'
  - 'linux_kernel >= 4.10, < 4.14.240'
  - 'linux_kernel >= 4.15, < 4.19.198'
  - 'linux_kernel >= 4.20, < 5.4.133'
  - 'linux_kernel >= 5.5, < 5.10.51'
  - 'linux_kernel >= 5.11, < 5.12.18'
  - 'linux_kernel >= 5.13, < 5.13.3'
  - e-series_santricity_os_controller
  - 'solidfire,_enterprise_sds_&_hci_storage_node'
  - solidfire_&_hci_management_node
  - brocade_fabric_operating_system_firmware
  - communications_cloud_native_core_binding_support_function = 22.1.3
  - communications_cloud_native_core_network_exposure_function = 22.1.1
  - communications_cloud_native_core_policy = 22.2.0
  - all_flash_fabric-attached_storage_8300_firmware
  - fabric-attached_storage_8300_firmware
  - all_flash_fabric-attached_storage_8700_firmware
  - fabric-attached_storage_8700_firmware
  - aff_a400_firmware
  - fabric-attached_storage_a400_firmware
  - hci_compute_node_firmware
  - h300e_firmware
  - h300s_firmware
  - h410c_firmware
  - h410s_firmware
  - h500e_firmware
  - h500s_firmware
  - h610c_firmware
  - h610s_firmware
  - h615c_firmware
  - h700e_firmware
  - h700s_firmware
patched:
  - linux_kernel 5.13.3
published: '2021-12-25'
updated: '2026-08-05'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2021-45485'
references:
  - url: 'https://arxiv.org/pdf/2112.09604.pdf'
    label: cve@mitre.org
  - url: 'https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.3'
    label: cve@mitre.org
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=62f20e068ccc50d6ab66fdb72ba90da2b9418c99
    label: cve@mitre.org
  - url: 'https://security.netapp.com/advisory/ntap-20220121-0001/'
    label: cve@mitre.org
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: cve@mitre.org
  - url: 'https://arxiv.org/pdf/2112.09604.pdf'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.13.3'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: >-
      https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=62f20e068ccc50d6ab66fdb72ba90da2b9418c99
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://security.netapp.com/advisory/ntap-20220121-0001/'
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.oracle.com/security-alerts/cpujul2022.html'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.03585
epssPercentile: 0.88954
ingestedAt: '2026-08-05T18:50:24.974Z'
exploits:
  github: 1
  githubRepos:
    - 'https://github.com/Satheesh575555/linux-4.19.72_CVE-2021-45485'
  checkedAt: '2026-09-25T08:20:39.921Z'
exploitAvailable: true
---

## Overview

In the IPv6 implementation in the Linux kernel before 5.13.3, net/ipv6/output_core.c has an information leak because of certain use of a hash table which, although big, doesn't properly consider that IPv6-based attackers can typically choose among many IPv6 source addresses.

## Affected

- `linux_kernel < 4.4.276`
- `linux_kernel >= 4.5, < 4.9.276`
- `linux_kernel >= 4.10, < 4.14.240`
- `linux_kernel >= 4.15, < 4.19.198`
- `linux_kernel >= 4.20, < 5.4.133`
- `linux_kernel >= 5.5, < 5.10.51`
- `linux_kernel >= 5.11, < 5.12.18`
- `linux_kernel >= 5.13, < 5.13.3`
- `e-series_santricity_os_controller`
- `solidfire,_enterprise_sds_&_hci_storage_node`
- `solidfire_&_hci_management_node`
- `brocade_fabric_operating_system_firmware`
- `communications_cloud_native_core_binding_support_function = 22.1.3`
- `communications_cloud_native_core_network_exposure_function = 22.1.1`
- `communications_cloud_native_core_policy = 22.2.0`
- `all_flash_fabric-attached_storage_8300_firmware`
- `fabric-attached_storage_8300_firmware`
- `all_flash_fabric-attached_storage_8700_firmware`
- `fabric-attached_storage_8700_firmware`
- `aff_a400_firmware`
- `fabric-attached_storage_a400_firmware`
- `hci_compute_node_firmware`
- `h300e_firmware`
- `h300s_firmware`
- `h410c_firmware`
- `h410s_firmware`
- `h500e_firmware`
- `h500s_firmware`
- `h610c_firmware`
- `h610s_firmware`
- `h615c_firmware`
- `h700e_firmware`
- `h700s_firmware`

## Remediation

Upgrade past the affected range:

- `linux_kernel 5.13.3`
