CVE-2012-3520
published 2012-10-03CVE-2012-3520: The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to…
PriorityP46low1.9CVSS 2.0
AVLACMAuNCNIPAN
EPSS
0.43%
35.6th percentile
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.
Affected
52 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.29-1 (bookworm) | linux 3.2.29-1 (bookworm) |
| linux | linux_kernel | <= 3.2.29 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:N/I:P/A:N
osv1.9LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-10-12·CVSS 1.9
CVE-2012-3520 [LOW] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to perform privileged actions as an administrator.
Pablo Neira Ayuso discovered a flaw in the credentials of netlink messages.
An unprivileged local attacker could exploit this by getting a netlink
based service, that relies on netlink credentials, to perform privileged
actions. (CVE-2012-3520)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Mathias Krause discovered an information leak in th
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-10-09·CVSS 1.9
CVE-2012-3520 [LOW] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to run actions or potentially programs as an
administrator.
Pablo Neira Ayuso discovered a flaw in the credentials of netlink messages.
An unprivileged local attacker could exploit this by getting a netlink
based service, that relies on netlink credentials, to perform privileged
actions. (CVE-2012-3520)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Mathias Krause discovered an infor
Red Hat
kernel: af_netlink: invalid handling of SCM_CREDENTIALS passing
vendor_redhat·2012-08-21·CVSS 1.9
CVE-2012-3520 [LOW] kernel: af_netlink: invalid handling of SCM_CREDENTIALS passing
kernel: af_netlink: invalid handling of SCM_CREDENTIALS passing
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.
Statement: This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5 and 6 as they did not backport the commit that introduced this issue. Future kernel updates for Red Hat Enterprise MRG 2 may address this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2012-3520: linux - The Netlink implementation in the Linux kernel before 3.2.30 does not properly h...
vendor_debian·2012·CVSS 1.9
CVE-2012-3520 [LOW] CVE-2012-3520: linux - The Netlink implementation in the Linux kernel before 3.2.30 does not properly h...
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.
Scope: local
bookworm: resolved (fixed in 3.2.29-1)
bullseye: resolved (fixed in 3.2.29-1)
forky: resolved (fixed in 3.2.29-1)
sid: resolved (fixed in 3.2.29-1)
trixie: resolved (fixed in 3.2.29-1)
GHSA
GHSA-fxmm-x2w5-24cg: The Netlink implementation in the Linux kernel before 3
ghsa_unreviewed·2022-05-17
CVE-2012-3520 [LOW] CWE-287 GHSA-fxmm-x2w5-24cg: The Netlink implementation in the Linux kernel before 3
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.
OSV
CVE-2012-3520: The Netlink implementation in the Linux kernel before 3
osv·2012-10-03·CVSS 1.9
CVE-2012-3520 [LOW] CVE-2012-3520: The Netlink implementation in the Linux kernel before 3
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.
Kernel
af_netlink: force credentials passing [CVE-2012-3520]
kernel_security·2012-08-21·CVSS 1.9
CVE-2012-3520 [LOW] af_netlink: force credentials passing [CVE-2012-3520]
af_netlink: force credentials passing [CVE-2012-3520]
Pablo Neira Ayuso discovered that avahi and
potentially NetworkManager accept spoofed Netlink messages because of a
kernel bug. The kernel passes all-zero SCM_CREDENTIALS ancillary data
to the receiver if the sender did not provide such data, instead of not
including any such data at all or including the correct data from the
peer (as it is the case with AF_UNIX).
This bug was introduced in commit 16e572626961
(af_unix: dont send SCM_CREDENTIALS by default)
This patch forces passing credentials for netlink, as
before the regression.
Another fix would be to not add SCM_CREDENTIALS in
netlink messages if not provided by the sender, but it
might break some programs.
With help from Florian Weimer & Petr Matousek
This issue is designat
Kernel
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
kernel_security·2012-08-21
CVE-2012-3520 Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
Merge git://git.kernel.org/pub/scm/linux/kernel/git/davem/net
Pull networking update from David Miller:
"A couple weeks of bug fixing in there. The largest chunk is all the
broken crap Amerigo Wang found in the netpoll layer."
1) netpoll and it's users has several serious bugs:
a) uses GFP_KERNEL with locks held
b) interfaces requiring interrupts disabled are called with them
enabled
c) and vice versa
d) VLAN tag demuxing, as per all other RX packet input paths, is not
applied
All from Amerigo Wang.
2) Hopefully cure the ipv4 mapped ipv6 address TCP early demux bugs for
good, from Neal Cardwell.
3) Unlike AF_UNIX, AF_PACKET sockets don't set a default credentials
when the user doesn't specify one explicitly during sendmsg().
Instead we attach an empty (zero) SCM credential block which
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2012-3520 kernel: af_netlink: invalid handling of SCM_CREDENTIALS passing [fedora-all]
bugzilla·2012-08-22·CVSS 1.9
CVE-2012-3520 [LOW] CVE-2012-3520 kernel: af_netlink: invalid handling of SCM_CREDENTIALS passing [fedora-all]
CVE-2012-3520 kernel: af_netlink: invalid handling of SCM_CREDENTIALS passing [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected Fedora
versions.
For comments that are specific to the vulnerability please use bugs filed
against "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please include this bug ID and the
bug IDs of this bug's parent bugs filed against the "Security Response"
product (the top-level CVE bugs). Please mention the CVE IDs being fixed
in the RPM changelog when available.
Bodhi update submission link:
https://admin.fedoraproject.org/updates/new/
Bugzilla
CVE-2012-3520 kernel: af_netlink: invalid handling of SCM_CREDENTIALS passing
bugzilla·2012-08-21·CVSS 1.9
CVE-2012-3520 [LOW] CVE-2012-3520 kernel: af_netlink: invalid handling of SCM_CREDENTIALS passing
CVE-2012-3520 kernel: af_netlink: invalid handling of SCM_CREDENTIALS passing
A flaw was found in the way Netlink messages without explicitly set SCM_CREDENTIALS were delivered. The kernel passes all-zero SCM_CREDENTIALS ancillary data to the receiver if the sender did not provide such data, instead of including the correct data from the peer (as it is the case with AF_UNIX). Programs that set SO_PASSCRED option on the Netlink socket and rely on SCM_CREDENTIALS for authentication might accept spoofed messages and perform privileged actions on behalf of the unprivileged attacker.
Introduced in:
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commitdiff;h=16e57262
Acknowledgements:
Red Hat would like to thank Pablo Neira Ayuso for reporting this issue.
Discussion:
St
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e0e3cea46d31d23dc40df0a49a7a2c04fe8edfeahttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00018.htmlhttp://secunia.com/advisories/50848http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.30http://www.openwall.com/lists/oss-security/2012/08/22/1http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/55152http://www.ubuntu.com/usn/USN-1599-1http://www.ubuntu.com/usn/USN-1610-1https://bugzilla.redhat.com/show_bug.cgi?id=850449https://github.com/torvalds/linux/commit/e0e3cea46d31d23dc40df0a49a7a2c04fe8edfeahttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e0e3cea46d31d23dc40df0a49a7a2c04fe8edfeahttp://lists.opensuse.org/opensuse-security-announce/2012-10/msg00005.htmlhttp://lists.opensuse.org/opensuse-updates/2013-02/msg00018.htmlhttp://secunia.com/advisories/50848http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.30http://www.openwall.com/lists/oss-security/2012/08/22/1http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.securityfocus.com/bid/55152http://www.ubuntu.com/usn/USN-1599-1http://www.ubuntu.com/usn/USN-1610-1https://bugzilla.redhat.com/show_bug.cgi?id=850449https://github.com/torvalds/linux/commit/e0e3cea46d31d23dc40df0a49a7a2c04fe8edfea
2012-10-03
Published