CVE-2012-3552
published 2012-10-03CVE-2012-3552: Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system…
PriorityP424medium5.9CVSS 3.1
AVNACHPRNUINSUCNINAH
EPSS
2.85%
85.2th percentile
Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of network traffic.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.0-1 (bookworm) | linux 3.0-1 (bookworm) |
| debian | linux | — | — |
| linux | linux_kernel | < 3.0 | 3.0 |
| linux | linux_kernel | >= 0 < 3.0-1 | 3.0-1 |
| linux | linux_kernel | >= 0 < 3.0-1 | 3.0-1 |
| linux | linux_kernel | >= 0 < 3.0-1 | 3.0-1 |
| linux | linux_kernel | >= 0 < 3.0-1 | 3.0-1 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_linux_eus | — | — |
CVSS provenance
nvdv3.15.9MEDIUMCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv5.9MEDIUM
vendor_debian5.9MEDIUM
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: IP_REPOPTS invalid free
vendor_redhat·2013-06-30·CVSS 5.9
CVE-2013-2224 [MEDIUM] kernel: net: IP_REPOPTS invalid free
kernel: net: IP_REPOPTS invalid free
A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows local users to cause a denial of service (invalid free operation and system crash) or possibly gain privileges via a sendmsg system call with the IP_RETOPTS option, as demonstrated by hemlock.c. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-3552.
Statement: This issue did not affect the version of the kernel package as shipped with Red Hat Enterprise MRG 2.
This issue affects the versions of Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. Future kernel updates for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6 may address this issue.
Package: kernel (Red Hat Enterprise Linux 7) -
Debian
CVE-2013-2224: linux - A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux ...
vendor_debian·2013·CVSS 5.9
CVE-2013-2224 [MEDIUM] CVE-2013-2224: linux - A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux ...
A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows local users to cause a denial of service (invalid free operation and system crash) or possibly gain privileges via a sendmsg system call with the IP_RETOPTS option, as demonstrated by hemlock.c. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-3552.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
Debian
CVE-2012-3552: linux - Race condition in the IP implementation in the Linux kernel before 3.0 might all...
vendor_debian·2012·CVSS 5.9
CVE-2012-3552 [MEDIUM] CVE-2012-3552: linux - Race condition in the IP implementation in the Linux kernel before 3.0 might all...
Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of network traffic.
Scope: local
bookworm: resolved (fixed in 3.0-1)
bullseye: resolved (fixed in 3.0-1)
forky: resolved (fixed in 3.0-1)
sid: resolved (fixed in 3.0-1)
trixie: resolved (fixed in 3.0-1)
Red Hat
kernel: net: slab corruption due to improper synchronization around inet->opt
vendor_redhat·2011-04-21·CVSS 5.9
CVE-2012-3552 [MEDIUM] kernel: net: slab corruption due to improper synchronization around inet->opt
kernel: net: slab corruption due to improper synchronization around inet->opt
Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of network traffic.
Statement: This issue did affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 5.
This issue did affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 6.
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterpise MRG 2.
Package: kernel (Red Hat Enterprise Linux Extended Update Support 6.2) - Affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
GHSA
GHSA-phqq-mhr3-p67h: A certain Red Hat patch for the Linux kernel 2
ghsa_unreviewed·2022-05-14·CVSS 5.9
CVE-2013-2224 [MEDIUM] GHSA-phqq-mhr3-p67h: A certain Red Hat patch for the Linux kernel 2
A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows local users to cause a denial of service (invalid free operation and system crash) or possibly gain privileges via a sendmsg system call with the IP_RETOPTS option, as demonstrated by hemlock.c. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-3552.
GHSA
GHSA-745g-xcgm-mj62: Race condition in the IP implementation in the Linux kernel before 3
ghsa_unreviewed·2022-05-13
CVE-2012-3552 [HIGH] CWE-362 GHSA-745g-xcgm-mj62: Race condition in the IP implementation in the Linux kernel before 3
Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of network traffic.
OSV
CVE-2012-3552: Race condition in the IP implementation in the Linux kernel before 3
osv·2012-10-03·CVSS 5.9
CVE-2012-3552 [MEDIUM] CVE-2012-3552: Race condition in the IP implementation in the Linux kernel before 3
Race condition in the IP implementation in the Linux kernel before 3.0 might allow remote attackers to cause a denial of service (slab corruption and system crash) by sending packets to an application that sets socket options during the handling of network traffic.
No detection rules found.
No public exploits indexed.
arXiv
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
arxiv_fulltext·2025-11-21
Characteristics, Root Causes, and Detection of Incomplete Security Bug Fixes in the Linux Kernel
Characteristics, Root Causes, and Detection of
Incomplete Security Bug Fixes in the Linux Kernel
Qiang Liu^1All work was done by Aug., 2022.,
Wenlong Zhang^1,
Muhui Jiang^2,1,
Lei Wu^1,
Yajin Zhou^1
^1Zhejiang University,
^2The Hong Kong Polytechnic University
## Abstract
Security bugs in the Linux kernel emerge endlessly and have attracted much
attention.
However, fixing security bugs in the Linux kernel could be incomplete due to
human mistakes.
Specifically, an incomplete fix fails to repair all the original security
defects in the software, fails to properly repair the original security defects,
or introduces new ones.
In this paper, we study the fixes of incomplete security bugs in the Linux
kernel for the first time, and reveal their characteristics, root causes as well
as de
Bugzilla
CVE-2013-2224 kernel: net: IP_REPOPTS invalid free
bugzilla·2013-07-01·CVSS 5.9
CVE-2013-2224 [MEDIUM] CVE-2013-2224 kernel: net: IP_REPOPTS invalid free
CVE-2013-2224 kernel: net: IP_REPOPTS invalid free
Linux kernel is found to be vulnerable to a denial of service and/or possible
code execution flaw caused by invalid free while sending message with
sendmsg(2) call with IP_RETOPTS socket option set. This option is set to pass
unprocessed IP options along with timestamps to a user via IP_OPTIONS control
message.
An unprivileged user/program could use this flaw to crash the system resulting
in DoS or possibly gain root privileges via arbitrary code execution.
Reference:
-> http://www.openwall.com/lists/oss-security/2013/06/30/1
This issue was introduced via Red Hat Enterprise Linux specific patch for CVE-2012-3552.
Discussion:
Statement:
This issue did not affect the version of the kernel package as shipped with Red Hat Enterprise MRG
Bugzilla
CVE-2012-3552 kernel: net: slab corruption due to improper synchronization around inet->opt
bugzilla·2012-08-31·CVSS 5.9
CVE-2012-3552 [MEDIUM] CVE-2012-3552 kernel: net: slab corruption due to improper synchronization around inet->opt
CVE-2012-3552 kernel: net: slab corruption due to improper synchronization around inet->opt
Description of the problem:
Lack proper synchronization to manipulate inet->opt ip_options can lead to system crash.
Problem is that ip_make_skb() calls ip_setup_cork() and ip_setup_cork() possibly makes a copy of ipc->opt (struct ip_options), without any protection against another thread manipulating inet->opt. Another thread can change inet->opt pointer and free old one under us.
Given right server application (setting socket options and processing traffic over the same socket at the same time), remote attacker could use this flaw to crash the system. More likely though, local unprivileged user could use this
flaw to crash the system.
Potential privilege escalation impact cannot be ruled out.
http://ftp.osuosl.org/pub/linux/kernel/v3.0/ChangeLog-3.0http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f6d8bd051c391c1c0458a30b2a7abcd939329259http://rhn.redhat.com/errata/RHSA-2012-1540.htmlhttp://www.openwall.com/lists/oss-security/2012/08/31/11https://bugzilla.redhat.com/show_bug.cgi?id=853465https://github.com/torvalds/linux/commit/f6d8bd051c391c1c0458a30b2a7abcd939329259http://ftp.osuosl.org/pub/linux/kernel/v3.0/ChangeLog-3.0http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f6d8bd051c391c1c0458a30b2a7abcd939329259http://rhn.redhat.com/errata/RHSA-2012-1540.htmlhttp://www.openwall.com/lists/oss-security/2012/08/31/11https://bugzilla.redhat.com/show_bug.cgi?id=853465https://github.com/torvalds/linux/commit/f6d8bd051c391c1c0458a30b2a7abcd939329259
2012-10-03
Published