CVE-2012-6537Sensitive Information Exposure in Linux

Severity
1.9LOWNVD
EPSS
0.1%
top 70.86%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 15
Latest updateMay 14

Description

net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability.

CVSS vector

AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9

Affected Packages3 packages

Debianlinux/linux_kernel< 3.2.32-1+3
NVDlinux/linux_kernel3.5.7+159
debiandebian/linux< linux 3.2.32-1 (bookworm)

Also affects: Enterprise Linux 5, 6.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-ffp2-8pxq-qc9h: net/xfrm/xfrm_user2022-05-14
OSV
CVE-2012-6537: net/xfrm/xfrm_user2013-03-15

📋Vendor Advisories

11
Ubuntu
Linux kernel (EC2) vulnerabilities2013-04-09
Ubuntu
Linux kernel vulnerabilities2013-04-08
Ubuntu
Linux kernel vulnerabilities2012-11-30
Ubuntu
Linux kernel vulnerabilities2012-11-30
Ubuntu
Linux kernel vulnerabilities2012-11-30

💬Community

1
Bugzilla
CVE-2012-6537 Kernel: xfrm_user information leaks copy_to_user_2013-03-16