Database/Kernel, userspace & hypervisor
Linux kernel (net/sched cls_route): Use-after-free in the cls_route filter
CVE-2022-2588Kernel, userspace & hypervisorcurated
Impact
Use-after-free in the cls_route filter - local privilege escalation, publicly exploited in container escapes
Who can reach it
Any tenant process in a container with CAP_NET_ADMIN in a userns
What to do
Livepatchable; otherwise drain + reboot. Blacklist cls_route module as a stopgap
References
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.