Database/Kernel, userspace & hypervisor
Linux kernel (net/sched cls_route): Use-after-free in the cls_route filter
CVSS 7.8CVE-2022-2588Kernel, userspace & hypervisorcurated
Impact
Use-after-free in the cls_route filter - local privilege escalation, publicly exploited in container escapes
Who can reach it
Any tenant process in a container with CAP_NET_ADMIN in a userns
What to do
Livepatchable; otherwise drain + reboot. Blacklist cls_route module as a stopgap
References
Related entries
- Xen on AMD-Vi - unity map handling on device reassignment: AMD-Vi unity mappings are not correctly torn down orCVE-2022-26358 · Xen on AMD-Vi - unity map handling on device reassignmentHigh
- Xen on AMD-Vi - unity map handling: Second XSA-400 AMD-Vi unity-map issue. Stale or incorrect IOMMU mappings acrossCVE-2022-26359 · Xen on AMD-Vi - unity map handlingHigh
- Xen on AMD-Vi - unity map handling: Third XSA-400 AMD-Vi issue. Same class - IOMMU mappings that outlive theirCVE-2022-26360 · Xen on AMD-Vi - unity map handlingHigh
- Xen on AMD-Vi - unity map handling: Fourth XSA-400 AMD-Vi issue. Patch the set togetherCVE-2022-26361 · Xen on AMD-Vi - unity map handlingHigh
- Linux kernel (IPsec ESP): Buffer overflow in the IPsec ESP transformation code - local rootCVE-2022-27666 · Linux kernel (IPsec ESP)High
- Linux kernel (netfilter): Use-after-free write in the netfilter subsystem - privilege escalation to rootCVE-2022-32250 · Linux kernel (netfilter)High
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.