CVE-2012-3510
published 2012-10-03CVE-2012-3510: Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially…
PriorityP418medium5.6CVSS 2.0
AVLACLAuNCPINAC
EPSS
0.51%
40.5th percentile
Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKSTATS_CMD_ATTR_PID command.
Affected
139 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 2.6.20-1 (bookworm) | linux 2.6.20-1 (bookworm) |
| linux | linux_kernel | <= 2.6.18.8 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.05.6MEDIUMAV:L/AC:L/Au:N/C:P/I:N/A:C
osv5.6MEDIUM
vendor_debian5.6MEDIUM
vendor_redhat5.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2012-3510: linux - Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in...
vendor_debian·2012·CVSS 5.6
CVE-2012-3510 [MEDIUM] CVE-2012-3510: linux - Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in...
Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKSTATS_CMD_ATTR_PID command.
Scope: local
bookworm: resolved (fixed in 2.6.20-1)
bullseye: resolved (fixed in 2.6.20-1)
forky: resolved (fixed in 2.6.20-1)
sid: resolved (fixed in 2.6.20-1)
trixie: resolved (fixed in 2.6.20-1)
Red Hat
kernel: taskstats: use-after-free in xacct_add_tsk()
vendor_redhat·2006-10-30·CVSS 5.6
CVE-2012-3510 [MEDIUM] CWE-416 kernel: taskstats: use-after-free in xacct_add_tsk()
kernel: taskstats: use-after-free in xacct_add_tsk()
Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKSTATS_CMD_ATTR_PID command.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red
Hat Enterprise Linux 6 and Red Hat Enterprise MRG as they already contain
upstream commit f0ec1aaf54cadd that fixed this issue.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
GHSA
GHSA-4w6j-x36r-qm6j: Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct
ghsa_unreviewed·2022-05-17
CVE-2012-3510 [MEDIUM] GHSA-4w6j-x36r-qm6j: Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct
Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKSTATS_CMD_ATTR_PID command.
OSV
CVE-2012-3510: Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct
osv·2012-10-03·CVSS 5.6
CVE-2012-3510 [MEDIUM] CVE-2012-3510: Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct
Use-after-free vulnerability in the xacct_add_tsk function in kernel/tsacct.c in the Linux kernel before 2.6.19 allows local users to obtain potentially sensitive information from kernel memory or cause a denial of service (system crash) via a taskstats TASKSTATS_CMD_ATTR_PID command.
No detection rules found.
No public exploits indexed.
http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.19http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f0ec1aaf54caddd21c259aea8b2ecfbde4ee4fb9http://rhn.redhat.com/errata/RHSA-2012-1323.htmlhttp://secunia.com/advisories/50811http://www.openwall.com/lists/oss-security/2012/08/20/12http://www.securityfocus.com/bid/55144http://www.securitytracker.com/id?1027602https://bugzilla.redhat.com/show_bug.cgi?id=849722https://github.com/torvalds/linux/commit/f0ec1aaf54caddd21c259aea8b2ecfbde4ee4fb9http://ftp.osuosl.org/pub/linux/kernel/v2.6/ChangeLog-2.6.19http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f0ec1aaf54caddd21c259aea8b2ecfbde4ee4fb9http://rhn.redhat.com/errata/RHSA-2012-1323.htmlhttp://secunia.com/advisories/50811http://www.openwall.com/lists/oss-security/2012/08/20/12http://www.securityfocus.com/bid/55144http://www.securitytracker.com/id?1027602https://bugzilla.redhat.com/show_bug.cgi?id=849722https://github.com/torvalds/linux/commit/f0ec1aaf54caddd21c259aea8b2ecfbde4ee4fb9
2012-10-03
Published