CVE-2012-6689
published 2016-05-02CVE-2012-6689: The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have…
PriorityP334high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.31%
23.0th percentile
The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.6.4-1 (bookworm) | linux 3.6.4-1 (bookworm) |
| linux | linux_kernel | < 3.0.44 | 3.0.44 |
| linux | linux_kernel | >= 0 < 3.6.4-1 | 3.6.4-1 |
| linux | linux_kernel | >= 0 < 3.6.4-1 | 3.6.4-1 |
| linux | linux_kernel | >= 0 < 3.6.4-1 | 3.6.4-1 |
| linux | linux_kernel | >= 0 < 3.6.4-1 | 3.6.4-1 |
| linux | linux_kernel | >= 3.1 < 3.2.30 | 3.2.30 |
| linux | linux_kernel | >= 3.3 < 3.4.12 | 3.4.12 |
| linux | linux_kernel | >= 3.5 < 3.5.5 | 3.5.5 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w4w5-pfmx-65jc: The netlink_sendmsg function in net/netlink/af_netlink
ghsa_unreviewed·2022-05-17
CVE-2012-6689 [HIGH] CWE-284 GHSA-w4w5-pfmx-65jc: The netlink_sendmsg function in net/netlink/af_netlink
The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.
OSV
CVE-2012-6689: The netlink_sendmsg function in net/netlink/af_netlink
osv·2016-05-02·CVSS 7.8
CVE-2012-6689 [HIGH] CVE-2012-6689: The netlink_sendmsg function in net/netlink/af_netlink
The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.
Red Hat
libmnl: incorrect validation of netlink message origin allows attackers to spoof netlink messages
vendor_redhat·2015-02-06·CVSS 7.8
CVE-2012-6689 [HIGH] libmnl: incorrect validation of netlink message origin allows attackers to spoof netlink messages
libmnl: incorrect validation of netlink message origin allows attackers to spoof netlink messages
The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-10-12·CVSS 1.9
CVE-2012-3520 [LOW] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to perform privileged actions as an administrator.
Pablo Neira Ayuso discovered a flaw in the credentials of netlink messages.
An unprivileged local attacker could exploit this by getting a netlink
based service, that relies on netlink credentials, to perform privileged
actions. (CVE-2012-3520)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Mathias Krause discovered an information leak in th
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-10-09·CVSS 1.9
CVE-2012-3520 [LOW] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to run actions or potentially programs as an
administrator.
Pablo Neira Ayuso discovered a flaw in the credentials of netlink messages.
An unprivileged local attacker could exploit this by getting a netlink
based service, that relies on netlink credentials, to perform privileged
actions. (CVE-2012-3520)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Mathias Krause discovered an infor
Debian
CVE-2012-6689: linux - The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel bef...
vendor_debian·2012·CVSS 7.8
CVE-2012-6689 [HIGH] CVE-2012-6689: linux - The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel bef...
The netlink_sendmsg function in net/netlink/af_netlink.c in the Linux kernel before 3.5.5 does not validate the dst_pid field, which allows local users to have an unspecified impact by spoofing Netlink messages.
Scope: local
bookworm: resolved (fixed in 3.6.4-1)
bullseye: resolved (fixed in 3.6.4-1)
forky: resolved (fixed in 3.6.4-1)
sid: resolved (fixed in 3.6.4-1)
trixie: resolved (fixed in 3.6.4-1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=20e1db19db5d6b9e4e83021595eab0dc8f107befhttp://marc.info/?l=linux-netdev&m=134522422125983&w=2http://marc.info/?l=linux-netdev&m=134522422925986&w=2http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.5http://www.openwall.com/lists/oss-security/2015/02/22/10http://www.securityfocus.com/bid/72739https://bugzilla.redhat.com/show_bug.cgi?id=848949https://github.com/torvalds/linux/commit/20e1db19db5d6b9e4e83021595eab0dc8f107befhttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=20e1db19db5d6b9e4e83021595eab0dc8f107befhttp://marc.info/?l=linux-netdev&m=134522422125983&w=2http://marc.info/?l=linux-netdev&m=134522422925986&w=2http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.5http://www.openwall.com/lists/oss-security/2015/02/22/10http://www.securityfocus.com/bid/72739https://bugzilla.redhat.com/show_bug.cgi?id=848949https://github.com/torvalds/linux/commit/20e1db19db5d6b9e4e83021595eab0dc8f107bef
2016-05-02
Published