cbcvebase.
CVE-2021-3715
published 2022-03-02

CVE-2021-3715: A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of…

PriorityP343high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.35%
27.6th percentile
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 5.5.17-1 (bookworm)linux 5.5.17-1 (bookworm)
linuxlinux_kernel
linuxlinux_kernel>= 0 < 5.5.17-15.5.17-1
linuxlinux_kernel>= 0 < 5.5.17-15.5.17-1
linuxlinux_kernel>= 0 < 5.5.17-15.5.17-1
linuxlinux_kernel>= 0 < 5.5.17-15.5.17-1
linuxlinux_kernel>= 0 < 4.4.0-203.2354.4.0-203.235
linuxlinux_kernel>= 0 < 4.15.0-136.1404.15.0-136.140
linuxlinux_kernel>= 0 < 5.4.0-70.785.4.0-70.78
linuxlinux_kernel>= 3.18 < 4.4.2184.4.218
linuxlinux_kernel>= 4.10 < 4.14.1754.14.175
linuxlinux_kernel>= 4.15 < 4.19.1144.19.114
linuxlinux_kernel>= 4.20 < 5.4.295.4.29
linuxlinux_kernel>= 4.5 < 4.9.2184.9.218
linuxlinux_kernel>= 5.5.0 < 5.5.145.5.14

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu4.4MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.