CVE-2012-6542Sensitive Information Exposure in Linux

Severity
1.9LOWNVD
EPSS
0.1%
top 69.13%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 15
Latest updateMay 14

Description

The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that leverages an uninitialized pointer argument.

CVSS vector

AV:L/AC:M/C:P/I:N/A:NExploitability: 3.4 | Impact: 2.9

Affected Packages3 packages

Debianlinux/linux_kernel< 3.2.30-1+3
NVDlinux/linux_kernel3.5.7+159
debiandebian/linux< linux 3.2.30-1 (bookworm)

Also affects: Enterprise Linux 5, 6.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-vwvf-8m35-552r: The llc_ui_getname function in net/llc/af_llc2022-05-14
OSV
CVE-2012-6542: The llc_ui_getname function in net/llc/af_llc2013-03-15

📋Vendor Advisories

9
Ubuntu
Linux kernel (EC2) vulnerabilities2013-04-25
Ubuntu
Linux kernel vulnerabilities2013-04-19
Ubuntu
Linux kernel vulnerabilities2012-11-30
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities2012-11-30
Ubuntu
Linux kernel (OMAP4) vulnerabilities2012-11-30

💬Community

1
Bugzilla
CVE-2012-6542 Kernel: llc: information leak via getsockname2013-03-16