VULNERABILITY INTELLIGENCE
CVE-2012-2136
CVSS score7.2 HIGH
EPSS probability0.58%
CISA KEVNot currently listed
Published2012-08-09
Last modified2026-06-16
CVSS vectorAV:L/AC:L/Au:N/C:C/I:C/A:C
Description
The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privileges by leveraging access to a TUN/TAP device.
Weakness classification
- CWE-20: Improper Input Validation
Primary references
- secalert@redhat.com — Broken Link
- secalert@redhat.com — Third Party Advisory, VDB Entry
- secalert@redhat.com — Third Party Advisory
- secalert@redhat.com — URL Repurposed
- secalert@redhat.com — Third Party Advisory
- secalert@redhat.com — Vendor Advisory
- secalert@redhat.com — Third Party Advisory, VDB Entry
- secalert@redhat.com — Third Party Advisory
- secalert@redhat.com — Issue Tracking
- secalert@redhat.com — Exploit, Patch
- af854a3a-2127-422b-91ae-364da2661108 — Broken Link
- af854a3a-2127-422b-91ae-364da2661108 — Third Party Advisory, VDB Entry