CVE-2021-3715
HIGH 7.8EPSS 0.4%
A flaw was found in the "Routing decision" classifier in the Linux kernel's Traffic Control networking subsystem in the way it handled changing of classification filters, leading to a use-after-free condition. This flaw allows unprivileged local users to escalate their privileges on the system. The highest threat from this vulnerability is to confidentiality, integrity, as well as system availability.
- CVSS v3.1
- 7.8 HIGH
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 0.35% chance of exploitation in the next 30 days, 28th percentile
- Published
- 2022-03-02
- Updated
- 2024-08-03
Proof-of-concept exploits (4)
- Igr1s-red/CVE-2022-25880★ · 2025-06-25
- Markakd/CVE-2022-2588487★ · 2023-03-04
- Markakd/kernel_exploit13★ · 2021-10-06
- dom4570/CVE-2022-25880★ · 2023-03-09