Description
The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privileges by leveraging access to a TUN/TAP device.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2012-2136 | The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privileges by leveraging access to a TUN/TAP device. |
Ubuntu USN |
USN-1514-1 | Linux kernel (OMAP4) vulnerabilities |
Ubuntu USN |
USN-1529-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1530-1 | Linux kernel (OMAP4) vulnerabilities |
Ubuntu USN |
USN-1531-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1532-1 | Linux kernel (OMAP4) vulnerabilities |
Ubuntu USN |
USN-1533-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1534-1 | Linux kernel (EC2) vulnerabilities |
Ubuntu USN |
USN-1535-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-1538-1 | Linux kernel (Natty backport) vulnerabilities |
Ubuntu USN |
USN-1539-1 | Linux kernel (Oneiric backport) vulnerabilities |
Ubuntu USN |
USN-1598-1 | Linux kernel vulnerability |
References
History
No history.
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2024-08-06T19:26:08.141Z
Reserved: 2012-04-04T00:00:00.000Z
Link: CVE-2012-2136
No data.
Status : Modified
Published: 2012-08-09T10:29:46.870
Modified: 2026-04-29T01:13:23.040
Link: CVE-2012-2136
OpenCVE Enrichment
No data.
EUVD
Ubuntu USN