CVE-2012-2669
published 2012-12-27CVE-2012-2669: The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages…
PriorityP45low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.35%
28.1th percentile
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.
Affected
115 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.23-1 (bookworm) | linux 3.2.23-1 (bookworm) |
| linux | linux_kernel | <= 3.7.1 | — |
| linux | linux_kernel | <= 3.4.4 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_ubuntu5.2MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-02-14·CVSS 2.1
CVE-2012-2669 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that hypervkvpd, which is distributed in the Linux
kernel, was not correctly validating the origin on Netlink messages. An
untrusted local user can cause a denial of service of Linux guests in
Hyper-V virtualization environments. (CVE-2012-2669)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Florian Weimer discovered that hypervkvpd, which is distributed in the
Linux kernel, was not correctly validating source addresses of netlink
packets. An untrusted local user can cause a denial of service by causing
hypervkvpd to exit. (
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2013-02-12·CVSS 2.1
CVE-2012-2669 [LOW] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that hypervkvpd, which is distributed in the Linux
kernel, was not correctly validating the origin on Netlink messages. An
untrusted local user can cause a denial of service of Linux guests in
Hyper-V virtualization environments. (CVE-2012-2669)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
Instructions: After a stand
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-02-12·CVSS 2.1
CVE-2012-2669 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that hypervkvpd, which is distributed in the Linux
kernel, was not correctly validating the origin on Netlink messages. An
untrusted local user can cause a denial of service of Linux guests in
Hyper-V virtualization environments. (CVE-2012-2669)
Dmitry Monakhov reported a race condition flaw the Linux ext4 filesystem
that can expose stale data. An unprivileged user could exploit this flaw to
cause an information leak. (CVE-2012-4508)
Florian Weimer discovered that hypervkvpd, which is distributed in the
Linux kernel, was not correctly validating source addresses of netlink
packets. An untrusted local user can cause a denial of service by causing
hypervkvpd to exit. (CVE-2012
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 5.2
CVE-2012-2119 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's macvtap device driver, which is
used in KVM (Kernel-based Virtual Machine) to create a network bridge
between host and guest. A privleged user in a guest could exploit this flaw
to crash the host, if the vhost_net module is loaded with the
experimental_zcopytx option enabled. (CVE-2012-2119)
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
A flaw was found in how the Linux kernel's KVM (
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 5.2
CVE-2012-2119 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's macvtap device driver, which is
used in KVM (Kernel-based Virtual Machine) to create a network bridge
between host and guest. A privleged user in a guest could exploit this flaw
to crash the host, if the vhost_net module is loaded with the
experimental_zcopytx option enabled. (CVE-2012-2119)
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
A flaw was found in how the Linux kernel
Red Hat
hypervkvpd: Netlink source address validation allows denial of service
vendor_redhat·2012-06-06·CVSS 2.1
CVE-2012-5532 [LOW] hypervkvpd: Netlink source address validation allows denial of service
hypervkvpd: Netlink source address validation allows denial of service
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2669.
Statement: The Red Hat Security Response Team has rated this issue as having low security impact. A future update may address this issue. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.
Package: hypervkvpd (Red Hat Enterprise Linux 6) - Not affected
Red Hat
hypervkvpd: fails to check origin of netlink messages
vendor_redhat·2012-05-08·CVSS 2.1
CVE-2012-2669 [LOW] hypervkvpd: fails to check origin of netlink messages
hypervkvpd: fails to check origin of netlink messages
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.
Statement: Not vulnerable. This issue did not affect the versions of hypvervkvpd as shipped with Red Hat Enterprise Linux 5.
Package: hypervkvpd (Red Hat Enterprise Linux 5) - Not affected
Package: hypervkvpd (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-2669: linux - The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in t...
vendor_debian·2012·CVSS 2.1
CVE-2012-2669 [LOW] CVE-2012-2669: linux - The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in t...
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.
Scope: local
bookworm: resolved (fixed in 3.2.23-1)
bullseye: resolved (fixed in 3.2.23-1)
forky: resolved (fixed in 3.2.23-1)
sid: resolved (fixed in 3.2.23-1)
trixie: resolved (fixed in 3.2.23-1)
GHSA
GHSA-8495-rmr5-jc76: The main function in tools/hv/hv_kvp_daemon
ghsa_unreviewed·2022-05-17
CVE-2012-2669 [LOW] CWE-20 GHSA-8495-rmr5-jc76: The main function in tools/hv/hv_kvp_daemon
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.
GHSA
GHSA-4mv9-4vrq-h2m3: The main function in tools/hv/hv_kvp_daemon
ghsa_unreviewed·2022-05-17·CVSS 2.1
CVE-2012-5532 [LOW] GHSA-4mv9-4vrq-h2m3: The main function in tools/hv/hv_kvp_daemon
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2669.
OSV
CVE-2012-2669: The main function in tools/hv/hv_kvp_daemon
osv·2012-12-27·CVSS 2.1
CVE-2012-2669 [LOW] CVE-2012-2669: The main function in tools/hv/hv_kvp_daemon
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.
OSV
CVE-2012-5532: The main function in tools/hv/hv_kvp_daemon
osv·2012-12-27·CVSS 2.1
CVE-2012-5532 [LOW] CVE-2012-5532: The main function in tools/hv/hv_kvp_daemon
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.8-rc1, allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-2669.
Kernel
Tools: hv: verify origin of netlink connector message
kernel_security·2012-05-31·CVSS 2.1
CVE-2012-2669 [LOW] Tools: hv: verify origin of netlink connector message
Tools: hv: verify origin of netlink connector message
The SuSE security team suggested to use recvfrom instead of recv to be
certain that the connector message is originated from kernel.
CVE-2012-2669
Signed-off-by: Olaf Hering
Signed-off-by: Marcus Meissner
Signed-off-by: Sebastian Krahmer
Signed-off-by: K. Y. Srinivasan
Cc: stable
Signed-off-by: Greg Kroah-Hartman
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-2669 hypervkvpd: fails to check origin of netlink messages
bugzilla·2013-01-09·CVSS 2.1
CVE-2012-2669 [LOW] CVE-2012-2669 hypervkvpd: fails to check origin of netlink messages
CVE-2012-2669 hypervkvpd: fails to check origin of netlink messages
The main function in tools/hv/hv_kvp_daemon.c in hypervkvpd, as distributed in the Linux kernel before 3.4.5, does not validate the origin of Netlink messages, which allows local users to spoof Netlink communication via a crafted connector message.
This is similar to CVE-2012-5532 (see bug #877572 for some of the confusion that happened with regards to the two CVEs).
This is corrected upstream via:
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=bcc2c9c3fff859e0eb019fe6fec26f9b8eba795c
And the fixed code is present in hypervkvpd-0-0.7.el5 as provided by Red Hat Enterprise Linux 5.
Statement:
Not vulnerable. This issue did not affect the versions of hypvervkvpd as shipped with Red Hat Ent
Bugzilla
CVE-2012-5532 hypervkvpd: Netlink source address validation allows denial of service
bugzilla·2012-11-16·CVSS 2.1
CVE-2012-5532 [LOW] CVE-2012-5532 hypervkvpd: Netlink source address validation allows denial of service
CVE-2012-5532 hypervkvpd: Netlink source address validation allows denial of service
Florian Weimer of the Red Hat Product Security Team discovered that hypervkvpd
would exit when it processed a spoofed Netlink packet that had been sent from
an untrusted local user, in the following code:
len = recvfrom(fd, kvp_recv_buffer, sizeof(kvp_recv_buffer), 0,
addr_p, &addr_l);
if (len < 0 || addr.nl_pid) {
syslog(LOG_ERR, "recvfrom failed; pid:%u error:%d %s",
addr.nl_pid, errno, strerror(errno));
close(fd);
return -1;
}
Acknowledgements:
This issue was discovered by Florian Weimer of the Red Hat Product Security
Team.
Discussion:
Upstream commit:
https://git.kernel.org/?p=linux/kernel/git/gregkh/char-misc.git;a=commit;h=95a69adab9acfc3981c504737a2b6578e4d846ef
---
Statement:
The Red H
arXiv
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
arxiv_fulltext·2025-11-21
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
Characteristics, Root Causes, and Detection of
Incomplete Security Bug Fixes in the Linux Kernel
Qiang Liu^1All work was done by Aug., 2022.,
Wenlong Zhang^1,
Muhui Jiang^2,1,
Lei Wu^1,
Yajin Zhou^1
^1Zhejiang University,
^2The Hong Kong Polytechnic University
## Abstract
Security bugs in the Linux kernel emerge endlessly and have attracted much
attention.
However, fixing security bugs in the Linux kernel could be incomplete due to
human mistakes.
Specifically, an incomplete fix fails to repair all the original security
defects in the software, fails to properly repair the original security defects,
or introduces new ones.
In this paper, we study the fixes of incomplete security bugs in the Linux
kernel for the first time, and reveal their characteristics, root causes as well
as de
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=bcc2c9c3fff859e0eb019fe6fec26f9b8eba795chttp://lists.opensuse.org/opensuse-updates/2012-11/msg00042.htmlhttp://openwall.com/lists/oss-security/2012/06/06/12http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.5http://www.openwall.com/lists/oss-security/2012/11/27/12https://bugzilla.novell.com/show_bug.cgi?id=761200https://github.com/torvalds/linux/commit/bcc2c9c3fff859e0eb019fe6fec26f9b8eba795chttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=bcc2c9c3fff859e0eb019fe6fec26f9b8eba795chttp://lists.opensuse.org/opensuse-updates/2012-11/msg00042.htmlhttp://openwall.com/lists/oss-security/2012/06/06/12http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.5http://www.openwall.com/lists/oss-security/2012/11/27/12https://bugzilla.novell.com/show_bug.cgi?id=761200https://github.com/torvalds/linux/commit/bcc2c9c3fff859e0eb019fe6fec26f9b8eba795c
2012-12-27
Published