CVE-2021-3715
published 2022-03-02CVE-2021-3715: A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of…
PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.35%
27.6th percentile
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 5.5.17-1 (bookworm) | linux 5.5.17-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 5.5.17-1 | 5.5.17-1 |
| linux | linux_kernel | >= 0 < 5.5.17-1 | 5.5.17-1 |
| linux | linux_kernel | >= 0 < 5.5.17-1 | 5.5.17-1 |
| linux | linux_kernel | >= 0 < 5.5.17-1 | 5.5.17-1 |
| linux | linux_kernel | >= 0 < 4.4.0-203.235 | 4.4.0-203.235 |
| linux | linux_kernel | >= 0 < 4.15.0-136.140 | 4.15.0-136.140 |
| linux | linux_kernel | >= 0 < 5.4.0-70.78 | 5.4.0-70.78 |
| linux | linux_kernel | >= 3.18 < 4.4.218 | 4.4.218 |
| linux | linux_kernel | >= 4.10 < 4.14.175 | 4.14.175 |
| linux | linux_kernel | >= 4.15 < 4.19.114 | 4.19.114 |
| linux | linux_kernel | >= 4.20 < 5.4.29 | 5.4.29 |
| linux | linux_kernel | >= 4.5 < 4.9.218 | 4.9.218 |
| linux | linux_kernel | >= 5.5.0 < 5.5.14 | 5.5.14 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Kernel Live Patch Security Notice
vendor_ubuntu·2021-11-11·CVSS 4.4
CVE-2020-29660 [MEDIUM] Kernel Live Patch Security Notice
Title: Kernel Live Patch Security Notice
Summary: Several security issues were fixed in the kernel.
Jann Horn discovered that the tty subsystem of the Linux kernel did not use
consistent locking in some situations, leading to a read-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information (kernel memory).(CVE-2020-29660)
Jann Horn discovered a race condition in the tty subsystem of the Linux
kernel in the locking for the TIOCSPGRP ioctl(), leading to a use-after-
free vulnerability. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code.(CVE-2020-29661)
De4dCr0w of 360 Alpha Lab discovered that the BPF verifier in the Linux
kernel did not properl
Red Hat
kernel: use-after-free in route4_change() in net/sched/cls_route.c
vendor_redhat·2021-09-07·CVSS 7.8
CVE-2021-3715 [HIGH] CWE-416 kernel: use-after-free in route4_change() in net/sched/cls_route.c
kernel: use-after-free in route4_change() in net/sched/cls_route.c
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this v
Debian
CVE-2021-3715: linux - A flaw was found in the "Routing decision" classifier in the Linux kernel's Traf...
vendor_debian·2021·CVSS 7.8
CVE-2021-3715 [HIGH] CVE-2021-3715: linux - A flaw was found in the "Routing decision" classifier in the Linux kernel's Traf...
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
Scope: local
bookworm: resolved (fixed in 5.5.17-1)
bullseye: resolved (fixed in 5.5.17-1)
forky: resolved (fixed in 5.5.17-1)
sid: resolved (fixed in 5.5.17-1)
trixie: resolved (fixed in 5.5.17-1)
GHSA
GHSA-gcff-f9p7-hmfg: A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of cla
ghsa_unreviewed·2022-03-04
CVE-2021-3715 [HIGH] CWE-416 GHSA-gcff-f9p7-hmfg: A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of cla
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
OSV
CVE-2021-3715: A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of cla
osv·2022-03-02·CVSS 7.8
CVE-2021-3715 [HIGH] CVE-2021-3715: A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of cla
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
OSV
Kernel Live Patch Security Notice
osv·2021-11-11·CVSS 4.4
CVE-2020-29660 [MEDIUM] Kernel Live Patch Security Notice
Kernel Live Patch Security Notice
Jann Horn discovered that the tty subsystem of the Linux kernel did not use
consistent locking in some situations, leading to a read-after-free
vulnerability. A local attacker could use this to cause a denial of service
(system crash) or possibly expose sensitive information (kernel memory).(CVE-2020-29660)
Jann Horn discovered a race condition in the tty subsystem of the Linux
kernel in the locking for the TIOCSPGRP ioctl(), leading to a use-after-
free vulnerability. A local attacker could use this to cause a denial of
service (system crash) or possibly execute arbitrary code.(CVE-2020-29661)
De4dCr0w of 360 Alpha Lab discovered that the BPF verifier in the Linux
kernel did not properly handle mod32 destination register truncation when
the source regi
No detection rules found.
No public exploits indexed.
2022-03-02
Published