iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, are sometimes a configuration option offered to end users. Even when setuid is used, other factors (such as C library configuration) may block exploitability.
CVSS Details
- CVSS 3.1 Base Score: 4.4
- CVSS 3.1 Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Alpine Linux | — | Upgrade iproute2 | Jun 16, 2020 | May 9, 2020 |
| Debian | — | Upgrade iproute2 | Jul 30, 2024 | May 9, 2020 |
| Gentoo Linux | — | Upgrade sys-apps/iproute2. | Aug 10, 2020 | May 9, 2020 |
| Huawei Euleros 2_0_sp5 | — | Upgrade iproute | Mar 22, 2022 | May 9, 2020 |
| Redhat_linux | — | No solution exists | Jul 9, 2025 | May 9, 2020 |
| Suse | — | Upgrade iproute2Upgrade libnetlink-devel | Oct 19, 2021 | May 9, 2020 |
| Ubuntu | — | Upgrade iproute2 | Jun 24, 2020 | May 9, 2020 |
| Vmware Photon_os | — | Use 'tdnf update' to upgrade all packages to the latest version. | Jan 20, 2025 | May 9, 2020 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub