Iproute2 is a foundational Linux networking utility suite embedded across distributions and container platforms for routing table and network device configuration, presenting a niche but deep footprint in critical system infrastructure. The observed vulnerabilities center on file-access ordering and memory-safety issues characteristic of low-level system tools, specifically link-following conditions and use-after-free flaws that arise in the manipulation of kernel interfaces. Current severity, exploitation activity, and exposure figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Iproute2 Project over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2019-20795MEDIUM iproute2 before 5.1.0 has a use-after-free in get_netnsid_from_name in ip/ipnetns.c. NOTE: security relevance may be limited to certain uses of setuid that, although not a default, | May 9, 2020 | 4.4 | 18 | NO | NO |
iproute2 before 3.3.0 allows local users to overwrite arbitrary files via a symlink attack on a temporary file used by (1) configure or (2) examples/dhcp-client-script. | Feb 15, 2014 | 3.3 | 15 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Iproute2 Project.
Media articles that mention a CVE ID that affects a product developed by Iproute2 Project — matched by CVE ID, not by vendor name.