CVE-2022-2588 is a use-after-free vulnerability in the Linux kernel cls_route traffic-control filter implementation, including route4_change(). When a filter handle has the value zero, an old filter can be freed without first being removed from its hash table, leaving a stale reference to freed memory.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
6 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
Repository purpose: a Linux kernel exploitation lab/PoC built around a custom vulnerable kernel driver interface (/dev/rdd) and an allocation primitive device (/dev/allocdev), with supporting VM tooling (disk image + initramfs) and GDB helper scripts for low-level memory/page-table/TLB inspection. Key components: - vmachine/exploit.c (C, ~22KB): main interactive exploit program. It defines a msg_t structure and three ioctls (RDD_ALLOC/RDD_FREE/RDD_READ) used to drive a kernel object lifecycle (allocate/free/read). It also implements heap spraying by repeatedly opening /dev/allocdev, and a timing side-channel using rdtsc around keyutils add_key() with an invalid description. The program includes routines to allocate a page and instruct the operator to convert it into a 1GB huge-page mapping by manually editing the PUD entry via GDB (walk_pgd script). It includes a TLB flush trick that relies on specific kernel configuration (KPTI enabled, PCID disabled). It can forward measurement results to the host via a virtio-serial port (/dev/virtio-ports/exploit_data), implying a QEMU-based setup. - gdbscripts/*.py (Python): custom GDB commands to (1) search QEMU TLB entries (monitor info tlb), (2) shift bytes in memory (manual patching), (3) walk a SLUB freelist from a head pointer and offset (heap debugging), and (4) walk page tables for a virtual address by reading CR3 and traversing PGD/PUD/PMD/PTE entries using a fixed phys->virt offset (0xffff888000000000). - scripts/pack_initramfs.sh and scripts/unpack_initramfs.sh (sh): manage initramfs.cpio.gz; pack script sets SUID on busybox inside initramfs (4755) and forces root ownership in the cpio archive. - setup.sh (bash): downloads Linux 6.2 tarball from kernel.org and creates/formats a 2GB raw disk image for the VM using qemu-img + losetup + mkfs.ext4. - vmachine/initramfs/bin/*: busybox applet stubs/symlinks for a minimal initramfs userland. Exploit capabilities (as implemented/observable from provided code excerpt): - Local kernel heap grooming: spray allocations via /dev/allocdev; obtain “fresh slab” and “populate slab” menu actions (functions referenced in the menu; full bodies not visible due to truncation). - Kernel object lifecycle control via /dev/rdd ioctls: allocate/free/read primitives (typical building blocks for UAF/infoleak exploitation). - Timing measurement around add_key() to infer allocation behavior; results can be exported to host via virtio-serial. - Page-table/TLB manipulation workflow assisted by GDB scripts, including guidance for creating huge-page mappings and flushing TLB under certain mitigations. No explicit CVE is referenced in the visible content; targeting appears to be a specific lab kernel (6.2) plus custom devices/drivers rather than a generic remote exploit. Overall maturity is best classified as PoC/lab exploit: interactive, environment-dependent, and requiring manual GDB steps for some stages.
This repository contains a local privilege escalation exploit for CVE-2022-2588, a double-free vulnerability in the Linux kernel's route4_filter implementation. The exploit is implemented in C (exploit.c) and is designed to work on a wide range of affected Linux distributions (kernels v3.17 to v5.19, before the fix). The exploit works by manipulating kernel memory via netlink and file operations, ultimately allowing the attacker to overwrite /etc/passwd and add a new root user with a known password. The Makefile provides a simple build command for the exploit. The README.md gives a detailed technical explanation of the vulnerability, exploitation strategy, and expected results, including a demonstration of successful privilege escalation. The exploit requires local access and user namespaces to be enabled. No network endpoints are targeted; the attack vector is purely local. The main fingerprintable endpoint is the /etc/passwd file, which is overwritten to achieve privilege escalation. Temporary files and symlinks in a directory 'exp_dir' are used as part of the exploitation process.
This repository contains a working exploit for CVE-2022-2588, a double-free vulnerability in the Linux kernel's route4_filter implementation. The exploit is implemented in C (exp_file_credential.c) and is designed to work on a wide range of Linux distributions and kernel versions (from v3.17 up to v5.19, before the fix). The Makefile is used to compile the exploit. The README.md provides a detailed technical explanation of the vulnerability, exploitation strategy, and usage instructions. The exploit leverages the double-free bug to achieve a use-after-free condition, which is then exploited to overwrite the /etc/passwd file. This results in the creation of a new root user with a known password, allowing the attacker to escalate privileges to root. The exploit requires user namespaces to be enabled and the ability to execute code on the target system. The attack vector is local privilege escalation, and the main fingerprintable endpoint is the /etc/passwd file, which is overwritten as part of the attack. The repository is well-documented, operational, and provides a real-world payload that grants root access by manipulating system credentials.
This repository contains three proof-of-concept (PoC) exploits targeting use-after-free (UAF) vulnerabilities in the Linux kernel, specifically CVE-2022-2585 (POSIX CPU timer UAF), CVE-2022-2586 (nf_tables cross-table reference UAF), and CVE-2022-2588 (cls_route UAF). The structure consists of three C source files, each corresponding to one CVE, and a README.md providing context and references. The exploits are local privilege escalation PoCs that interact directly with kernel interfaces (such as netlink sockets and kernel objects) to trigger UAF conditions. No weaponized payloads are included; the code is intended for research and demonstration purposes. The endpoints involved are local files, netlink sockets, and kernel objects/tables. The repository is suitable for researchers or defenders seeking to understand or test these vulnerabilities on affected Linux systems.
This repository contains proof-of-concept (POC) exploit code for three Linux kernel vulnerabilities: CVE-2022-2585, CVE-2022-2586, and CVE-2022-2588. The structure includes three C source files (CVE-2022-2585.c, CVE-2022-2586.c, dirtycred.c) and a README.md file. Each C file targets a specific kernel vulnerability: - CVE-2022-2585.c demonstrates a UAF in POSIX CPU timers by manipulating timer objects and process forking/cloning. - CVE-2022-2586.c exploits a UAF in the netfilter nf_tables subsystem by creating and deleting tables, sets, and objects via netlink sockets, using the libmnl and libnftnl libraries. - dirtycred.c (related to CVE-2022-2588) targets a UAF in the cls_route traffic control filter, using raw netlink messages to manipulate kernel networking structures. All exploits are local privilege escalation POCs and require the attacker to execute code on a vulnerable Linux system. The README provides references to the original advisories and research papers. No weaponized payloads are included; the code is intended for research and demonstration purposes.
This repository provides a working exploit for CVE-2022-2588, a double-free vulnerability in the Linux kernel's netfilter subsystem. The main exploit is implemented in 'exp.c', which orchestrates a series of heap manipulations and netlink operations to achieve a double-free condition, ultimately allowing the attacker to overwrite the /etc/passwd file and gain root privileges. The exploit is designed to be run in a QEMU virtual machine environment, as set up by 'boot.sh' and the provided Makefile, which compiles the exploit and launches a vulnerable kernel with a custom root filesystem. The 'poc.c' file serves as a proof-of-concept to interact with netlink and traffic control interfaces, demonstrating the vulnerability trigger. The exploit is operational and provides a working privilege escalation payload. Key fingerprintable endpoints include the target file /etc/passwd and temporary directories/files used during exploitation. The repository is structured for ease of testing in a controlled environment, with clear separation between the exploit, proof-of-concept, and environment setup scripts.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
26 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A Linux kernel use-after-free vulnerability in the cls_route traffic-control filter implementation. An old filter may be freed without first being removed from a hashtable when its handle is zero, potentially enabling local privilege escalation or other compromise.
A Linux kernel cls_route filter use-after-free vulnerability that may permit local privilege escalation.
Linux kernel use-after-free flaw in the cls_route filter implementation that may permit privilege escalation.
A use-after-free vulnerability in the Linux kernel cls_route filter implementation that may allow privilege escalation.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.