CVE-2012-3511
published 2012-10-04CVE-2012-3511: Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service…
PriorityP418medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.38%
30.4th percentile
Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service (use-after-free and system crash) via vectors involving a (1) munmap or (2) close system call.
Affected
86 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.23-1 (bookworm) | linux 3.2.23-1 (bookworm) |
| linux | linux_kernel | <= 3.4.4 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-09-21·CVSS 4.9
CVE-2012-2121 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's KVM (kernel virtual machine).
An administrative user in the guest OS could leverage this flaw to cause a
denial of service in the host OS. (CVE-2012-2121)
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
A flaw was discovered in the madvise feature of the Linux kerne
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2012-09-19·CVSS 7.8
CVE-2012-3412 [HIGH] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
A flaw was discovered in the madvise feature of the Linux kernel's memory
subsystem. An unprivileged local use could exploit the flaw to cause a
denial of service (crash the system). (CVE-2012-3511)
Instructions: After a standard system update you need to reboot y
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-09-19·CVSS 7.8
CVE-2012-3412 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
A flaw was discovered in the madvise feature of the Linux kernel's memory
subsystem. An unprivileged local use could exploit the flaw to cause a
denial of service (crash the system). (CVE-2012-3511)
Instructions: After a standard system update you need to reboot your co
Ubuntu
Linux kernel (Natty backport) vulnerabilities
vendor_ubuntu·2012-09-19·CVSS 4.7
CVE-2012-2745 [MEDIUM] Linux kernel (Natty backport) vulnerabilities
Title: Linux kernel (Natty backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was found in how the Linux kernel passed the replacement session
keyring to a child process. An unprivileged local user could exploit this
flaw to cause a denial of service (panic). (CVE-2012-2745)
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
A flaw was discovered in the madvise feature of
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-09-14·CVSS 4.7
CVE-2012-2745 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was found in how the Linux kernel passed the replacement session
keyring to a child process. An unprivileged local user could exploit this
flaw to cause a denial of service (panic). (CVE-2012-2745)
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
A flaw was discovered in the madvise feature of the Linux kernel'
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2012-08-14·CVSS 7.2
CVE-2012-2136 [HIGH] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
Ulrich Obergfell discovered an error in the Linux kernel's memory
management subsystem on 32 bit PAE systems with more than 4GB of memory
installed. A local unprivileged user could exploit this flaw to crash the
system. (CVE-2012-2373)
An error was discovered in the Linux kernel's memory subsystem (hugetlb).
An unprivileged local user could exploit this flaw to ca
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 5.2
CVE-2012-2119 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's macvtap device driver, which is
used in KVM (Kernel-based Virtual Machine) to create a network bridge
between host and guest. A privleged user in a guest could exploit this flaw
to crash the host, if the vhost_net module is loaded with the
experimental_zcopytx option enabled. (CVE-2012-2119)
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
A flaw was found in how the Linux kernel's KVM (
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 7.2
CVE-2012-2136 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
Ulrich Obergfell discovered an error in the Linux kernel's memory
management subsystem on 32 bit PAE systems with more than 4GB of memory
installed. A local unprivileged user could exploit this flaw to crash the
system. (CVE-2012-2373)
An error was discovered in the Linux kernel's memory subsystem (hugetlb).
An unprivileged local user could exploit this flaw to cause a denial of
ser
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 5.2
CVE-2012-2119 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's macvtap device driver, which is
used in KVM (Kernel-based Virtual Machine) to create a network bridge
between host and guest. A privleged user in a guest could exploit this flaw
to crash the host, if the vhost_net module is loaded with the
experimental_zcopytx option enabled. (CVE-2012-2119)
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
A flaw was found in how the Linux kernel
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-08-10·CVSS 7.2
CVE-2012-2136 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An error was discovered in the Linux kernel's network TUN/TAP device
implementation. A local user with access to the TUN/TAP interface (which is
not available to unprivileged users until granted by a root user) could
exploit this flaw to crash the system or potential gain administrative
privileges. (CVE-2012-2136)
Ulrich Obergfell discovered an error in the Linux kernel's memory
management subsystem on 32 bit PAE systems with more than 4GB of memory
installed. A local unprivileged user could exploit this flaw to crash the
system. (CVE-2012-2373)
A flaw was discovered in the Linux kernel's epoll system call. An
unprivileged local user could use this flaw to crash the system.
(CVE-2012-
Red Hat
kernel: mm: use-after-free in madvise_remove()
vendor_redhat·2012-07-06·CVSS 6.2
CVE-2012-3511 [MEDIUM] CWE-416 kernel: mm: use-after-free in madvise_remove()
kernel: mm: use-after-free in madvise_remove()
Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service (use-after-free and system crash) via vectors involving a (1) munmap or (2) close system call.
Debian
CVE-2012-3511: linux - Multiple race conditions in the madvise_remove function in mm/madvise.c in the L...
vendor_debian·2012·CVSS 6.2
CVE-2012-3511 [MEDIUM] CVE-2012-3511: linux - Multiple race conditions in the madvise_remove function in mm/madvise.c in the L...
Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service (use-after-free and system crash) via vectors involving a (1) munmap or (2) close system call.
Scope: local
bookworm: resolved (fixed in 3.2.23-1)
bullseye: resolved (fixed in 3.2.23-1)
forky: resolved (fixed in 3.2.23-1)
sid: resolved (fixed in 3.2.23-1)
trixie: resolved (fixed in 3.2.23-1)
GHSA
GHSA-vr2h-9prr-v3rg: Multiple race conditions in the madvise_remove function in mm/madvise
ghsa_unreviewed·2022-05-17
CVE-2012-3511 [MEDIUM] CWE-362 GHSA-vr2h-9prr-v3rg: Multiple race conditions in the madvise_remove function in mm/madvise
Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service (use-after-free and system crash) via vectors involving a (1) munmap or (2) close system call.
OSV
CVE-2012-3511: Multiple race conditions in the madvise_remove function in mm/madvise
osv·2012-10-04·CVSS 6.2
CVE-2012-3511 [MEDIUM] CVE-2012-3511: Multiple race conditions in the madvise_remove function in mm/madvise
Multiple race conditions in the madvise_remove function in mm/madvise.c in the Linux kernel before 3.4.5 allow local users to cause a denial of service (use-after-free and system crash) via vectors involving a (1) munmap or (2) close system call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3511 kernel: mm: use-after-free in madvise_remove()
bugzilla·2012-08-20·CVSS 6.2
CVE-2012-3511 [MEDIUM] CVE-2012-3511 kernel: mm: use-after-free in madvise_remove()
CVE-2012-3511 kernel: mm: use-after-free in madvise_remove()
A use-after-free flaw has been found in madvise_remove() function in the Linux kernel. madvise_remove() can race with munmap (causing a use-after-free
of the vma) or with close (causing a use-after-free of the struct file). An unprivileged local user can use this flaw to crash the system and potentially gain higher privileges.
Upstream fix:
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=9ab4233dd08036fe34a89c7dc6f47a8bf2eb29eb
Introduced in:
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=90ed52ebe48181d3c5427b3bd1d24f659e7575ad
Discussion:
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 849742]
---
Is there any fix released out now ?
-
arXiv
BEACON: Automatic Container Policy Generation using Environment-aware Dynamic Analysis
arxiv_fulltext·2025-11-29
BEACON: Automatic Container Policy Generation using Environment-aware Dynamic Analysis
=1em
1
.001
: Automatic Container Policy Generation using Environment-aware Dynamic Analysis
Kang et al.
[mode = title]: Automatic Container Policy Generation using Environment-aware Dynamic Analysis
[1]
[1]This is the accepted manuscript of an article accepted for publication in Computers & Security.
[1]Haney Kang[orcid=0000-0003-0866-0938]
[email protected]
[1]
[3]Eduard Marin[orcid=0000-0002-5002-0187]
[email protected]
[1]
[2]Myoungsung You[orcid=0000-0001-5822-5243]
[email protected]
[3]Diego Perino
[email protected]
[1]Seungwon Shin[orcid=0000-0002-1077-5606]
[email protected]
[4]Jinwoo Kim[orcid=0000-0003-1303-8668]
[email protected]
[1]
[fn1]Co-first authors
[cor1]Corresponding author
[1]
organization=School of Electrical Engineering, KAIST,
a
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9ab4233dd08036fe34a89c7dc6f47a8bf2eb29ebhttp://secunia.com/advisories/50633http://secunia.com/advisories/50732http://secunia.com/advisories/55055http://ubuntu.com/usn/usn-1529-1http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.5http://www.openwall.com/lists/oss-security/2012/08/20/13http://www.securityfocus.com/bid/55151http://www.ubuntu.com/usn/USN-1567-1http://www.ubuntu.com/usn/USN-1572-1http://www.ubuntu.com/usn/USN-1577-1https://bugzilla.redhat.com/show_bug.cgi?id=849734https://github.com/torvalds/linux/commit/9ab4233dd08036fe34a89c7dc6f47a8bf2eb29ebhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9ab4233dd08036fe34a89c7dc6f47a8bf2eb29ebhttp://secunia.com/advisories/50633http://secunia.com/advisories/50732http://secunia.com/advisories/55055http://ubuntu.com/usn/usn-1529-1http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.5http://www.openwall.com/lists/oss-security/2012/08/20/13http://www.securityfocus.com/bid/55151http://www.ubuntu.com/usn/USN-1567-1http://www.ubuntu.com/usn/USN-1572-1http://www.ubuntu.com/usn/USN-1577-1https://bugzilla.redhat.com/show_bug.cgi?id=849734https://github.com/torvalds/linux/commit/9ab4233dd08036fe34a89c7dc6f47a8bf2eb29eb
2012-10-04
Published