CVE-2012-3412
published 2012-10-03CVE-2012-3412: The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption…
PriorityP338high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
6.16%
92.8th percentile
The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 3.2.29-1 (bookworm) | linux 3.2.29-1 (bookworm) |
| linux | linux_kernel | < 3.0.44 | 3.0.44 |
| linux | linux_kernel | >= 0 < 3.2.29-1 | 3.2.29-1 |
| linux | linux_kernel | >= 0 < 3.2.29-1 | 3.2.29-1 |
| linux | linux_kernel | >= 0 < 3.2.29-1 | 3.2.29-1 |
| linux | linux_kernel | >= 0 < 3.2.29-1 | 3.2.29-1 |
| linux | linux_kernel | >= 3.1 < 3.2.30 | 3.2.30 |
| linux | linux_kernel | >= 3.3 < 3.4.12 | 3.4.12 |
| linux | linux_kernel | >= 3.5 < 3.5.5 | 3.5.5 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-09-21·CVSS 4.9
CVE-2012-2121 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
A flaw was discovered in the madvise feature of the Linux kerne
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-09-21·CVSS 7.8
CVE-2012-3412 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP
device driver. A local user could exploit this flaw to examine part of the
kernel's stack memory. (CVE-2012-6547)
A flaw was discovered in the requeuing of futexes in the Linux kernel. A
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-09-21·CVSS 7.8
CVE-2012-3412 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall al
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-09-21·CVSS 7.8
CVE-2012-3412 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP
device driver. A local user could exploit this flaw to examine part of the
kernel's stack memory. (CVE-2012-6547)
A flaw was discovered in the requeuing of futexes in the Linux kernel. A
local u
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2012-09-19·CVSS 7.8
CVE-2012-3412 [HIGH] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
A flaw was discovered in the madvise feature of the Linux kernel's memory
subsystem. An unprivileged local use could exploit the flaw to cause a
denial of service (crash the system). (CVE-2012-3511)
Instructions: After a standard system update you need to reboot y
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-09-19·CVSS 7.8
CVE-2012-3412 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
A flaw was discovered in the madvise feature of the Linux kernel's memory
subsystem. An unprivileged local use could exploit the flaw to cause a
denial of service (crash the system). (CVE-2012-3511)
Instructions: After a standard system update you need to reboot your co
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2012-09-19·CVSS 4.7
CVE-2012-2745 [MEDIUM] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was found in how the Linux kernel passed the replacement session
keyring to a child process. An unprivileged local user could exploit this
flaw to cause a denial of service (panic). (CVE-2012-2745)
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
A flaw was discovered in the madvise feature of
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-09-19·CVSS 7.8
CVE-2012-3412 [HIGH] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
r
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-09-14·CVSS 4.7
CVE-2012-2745 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was found in how the Linux kernel passed the replacement session
keyring to a child process. An unprivileged local user could exploit this
flaw to cause a denial of service (panic). (CVE-2012-2745)
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
A flaw was discovered in the madvise feature of the Linux kernel'
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-09-14·CVSS 7.8
CVE-2012-3412 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third
Red Hat
kernel: sfc: potential remote denial of service through TCP MSS option
vendor_redhat·2012-07-30·CVSS 7.8
CVE-2012-3412 [HIGH] CWE-400 kernel: sfc: potential remote denial of service through TCP MSS option
kernel: sfc: potential remote denial of service through TCP MSS option
The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Affected
Debian
CVE-2012-3412: linux - The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 all...
vendor_debian·2012·CVSS 7.8
CVE-2012-3412 [HIGH] CVE-2012-3412: linux - The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 all...
The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.
Scope: local
bookworm: resolved (fixed in 3.2.29-1)
bullseye: resolved (fixed in 3.2.29-1)
forky: resolved (fixed in 3.2.29-1)
sid: resolved (fixed in 3.2.29-1)
trixie: resolved (fixed in 3.2.29-1)
GHSA
GHSA-cx3f-qjc6-76hq: The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3
ghsa_unreviewed·2022-05-17
CVE-2012-3412 [HIGH] GHSA-cx3f-qjc6-76hq: The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3
The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.
OSV
CVE-2012-3412: The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3
osv·2012-10-03·CVSS 7.8
CVE-2012-3412 [HIGH] CVE-2012-3412: The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3
The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.
Kernel
net: Allow driver to limit number of GSO segments per skb
kernel_security·2012-07-30·CVSS 7.8
CVE-2012-3412 [HIGH] net: Allow driver to limit number of GSO segments per skb
net: Allow driver to limit number of GSO segments per skb
A peer (or local user) may cause TCP to use a nominal MSS of as little
as 88 (actual MSS of 76 with timestamps). Given that we have a
sufficiently prodigious local sender and the peer ACKs quickly enough,
it is nevertheless possible to grow the window for such a connection
to the point that we will try to send just under 64K at once. This
results in a single skb that expands to 861 segments.
In some drivers with TSO support, such an skb will require hundreds of
DMA descriptors; a substantial fraction of a TX ring or even more than
a full ring. The TX queue selected for the skb may stall and trigger
the TX watchdog repeatedly (since the problem skb will be retried
after the TX reset). This particularly affects sfc, for which the
is
Kernel
sfc: Fix maximum number of TSO segments and minimum TX queue size
kernel_security·2012-07-30·CVSS 7.8
CVE-2012-3412 [HIGH] sfc: Fix maximum number of TSO segments and minimum TX queue size
sfc: Fix maximum number of TSO segments and minimum TX queue size
Currently an skb requiring TSO may not fit within a minimum-size TX
queue. The TX queue selected for the skb may stall and trigger the TX
watchdog repeatedly (since the problem skb will be retried after the
TX reset). This issue is designated as CVE-2012-3412.
Set the maximum number of TSO segments for our devices to 100. This
should make no difference to behaviour unless the actual MSS is less
than about 700. Increase the minimum TX queue size accordingly to
allow for 2 worst-case skbs, so that there will definitely be space
to add an skb after we wake a queue.
To avoid invalidating existing configurations, change
efx_ethtool_set_ringparam() to fix up values that are too small rather
than returning -EINVAL.
Signed-off-b
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3412 kernel: sfc: potential remote denial of service through TCP MSS option [fedora-all]
bugzilla·2012-08-03·CVSS 7.8
CVE-2012-3412 [HIGH] CVE-2012-3412 kernel: sfc: potential remote denial of service through TCP MSS option [fedora-all]
CVE-2012-3412 kernel: sfc: potential remote denial of service through TCP MSS option [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updat
Bugzilla
CVE-2012-3412 kernel: sfc: potential remote denial of service through TCP MSS option
bugzilla·2012-07-31·CVSS 7.8
CVE-2012-3412 [HIGH] CVE-2012-3412 kernel: sfc: potential remote denial of service through TCP MSS option
CVE-2012-3412 kernel: sfc: potential remote denial of service through TCP MSS option
A peer (or local user) may cause TCP to use a nominal MSS of as little
as 88 (actual MSS of 76 with timestamps). Given that we have a
sufficiently prodigious local sender and the peer ACKs quickly enough,
it is nevertheless possible to grow the window for such a connection
to the point that we will try to send just under 64K at once. This
results in a single skb that expands to 861 segments.
In some drivers with TSO support, such an skb will require hundreds of
DMA descriptors; a substantial fraction of a TX ring or even more than
a full ring. The TX queue selected for the skb may stall and trigger
the TX watchdog repeatedly (since the problem skb will be retried
after the TX reset).
Upstream patch:
htt
http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1323.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1324.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1347.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1375.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1401.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1430.htmlhttp://secunia.com/advisories/50633http://secunia.com/advisories/50732http://secunia.com/advisories/50811http://secunia.com/advisories/51193http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.30http://www.openwall.com/lists/oss-security/2012/08/03/4http://www.ubuntu.com/usn/USN-1567-1http://www.ubuntu.com/usn/USN-1568-1http://www.ubuntu.com/usn/USN-1572-1http://www.ubuntu.com/usn/USN-1575-1http://www.ubuntu.com/usn/USN-1577-1http://www.ubuntu.com/usn/USN-1578-1http://www.ubuntu.com/usn/USN-1579-1http://www.ubuntu.com/usn/USN-1580-1https://bugzilla.redhat.com/show_bug.cgi?id=844714https://github.com/torvalds/linux/commit/68cb695ccecf949d48949e72f8ce591fdaaa325chttps://www.suse.com/support/update/announcement/2012/suse-su-20121679-1.htmlhttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1323.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1324.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1347.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1375.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1401.htmlhttp://rhn.redhat.com/errata/RHSA-2012-1430.htmlhttp://secunia.com/advisories/50633http://secunia.com/advisories/50732http://secunia.com/advisories/50811http://secunia.com/advisories/51193http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.30http://www.openwall.com/lists/oss-security/2012/08/03/4http://www.ubuntu.com/usn/USN-1567-1http://www.ubuntu.com/usn/USN-1568-1http://www.ubuntu.com/usn/USN-1572-1http://www.ubuntu.com/usn/USN-1575-1http://www.ubuntu.com/usn/USN-1577-1http://www.ubuntu.com/usn/USN-1578-1http://www.ubuntu.com/usn/USN-1579-1http://www.ubuntu.com/usn/USN-1580-1https://bugzilla.redhat.com/show_bug.cgi?id=844714https://github.com/torvalds/linux/commit/68cb695ccecf949d48949e72f8ce591fdaaa325chttps://www.suse.com/support/update/announcement/2012/suse-su-20121679-1.html
2012-10-03
Published