VULNERABILITY INTELLIGENCE

CVE-2012-2136

CVSS score7.2 HIGH
EPSS probability0.58%
CISA KEVNot currently listed
Published2012-08-09
Last modified2026-06-16
CVSS vectorAV:L/AC:L/Au:N/C:C/I:C/A:C

Description

The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privileges by leveraging access to a TUN/TAP device.

Weakness classification

  • CWE-20: Improper Input Validation

Primary references