CVE-2025-21702 is a high-severity vulnerability in the Linux kernel's networking subsystem, specifically impacting how queue lengths are managed within certain qdisc configurations. This flaw can create an inconsistent state between parent and child qdiscs, which can be leveraged for user-to-kernel privilege escalation. With a CVSS score of 7.0, exploitation requires local access and has high attack complexity. There is currently no public exploit code available, it is not known to be actively exploited, and community attention remains minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 2.6.34, < 5.4.291CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.5, < 5.10.235CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.11, < 5.15.179CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 5.16, < 6.1.130CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 6.2, < 6.6.83CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.1 Vendor Blog, and 0.0 Security Researcher mentions.
HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025HP ThinPro 8.1 SP8 Security Updates
Oct 27, 2025Linux Kernel Privilege Escalation on Container-Optimized OS nodes (CVE-2025-21702)
May 22, 2025Linux kernel privilege escalation on Container-Optimized OS nodes (CVE-2025-21702)
May 22, 2025Linux kernel privilege escalation on Container-Optimized OS nodes
May 22, 2025kernel: pfifo_tail_enqueue: Drop new packet when sch->limit == 0
Feb 18, 2025