CVE Database
/

CVE-2012-2136

Back to search

CVE-2012-2136

Published: Aug 9, 2012

Modified: Aug 6, 2024

PUBLISHED

Description

The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privileges by leveraging access to a TUN/TAP device.

VendorProductVersions

n/a

n/a

affected
n/a

References

RHSA-2012:0743
vendor-advisory
x_refsource_REDHAT
53721
vdb-entry
x_refsource_BID
USN-1535-1
vendor-advisory
x_refsource_UBUNTU
USN-1529-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2012:1087
vendor-advisory
x_refsource_REDHAT
50807
third-party-advisory
x_refsource_SECUNIA

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now