cbcvebase.
CVE-2012-2136
published 2012-08-09

CVE-2012-2136: The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local…

PriorityP430high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.58%
44.6th percentile
The sock_alloc_send_pskb function in net/core/sock.c in the Linux kernel before 3.4.5 does not properly validate a certain length value, which allows local users to cause a denial of service (heap-based buffer overflow and system crash) or possibly gain privileges by leveraging access to a TUN/TAP device.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.2.20-1 (bookworm)linux 3.2.20-1 (bookworm)
linuxlinux_kernel< 3.0.373.0.37
linuxlinux_kernel>= 0 < 3.2.20-13.2.20-1
linuxlinux_kernel>= 0 < 3.2.20-13.2.20-1
linuxlinux_kernel>= 0 < 3.2.20-13.2.20-1
linuxlinux_kernel>= 0 < 3.2.20-13.2.20-1
linuxlinux_kernel>= 3.1 < 3.2.233.2.23
linuxlinux_kernel>= 3.3 < 3.4.53.4.5

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.