PT-2012-1084 · Centos+2 · Centos+2

Florian Weimer

·

Published

2012-12-27

·

Updated

2024-06-15

·

CVE-2012-5532

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions hypervkvpd versions prior to 3.8-rc1 hypervkvpd-debuginfo-0 (affected versions not specified) Red Hat Enterprise Linux (affected versions not specified) CentOS (affected versions not specified)
Description The issue allows local users to cause a denial of service (daemon exit) via a crafted application that sends a Netlink message. This is due to an incorrect fix in the main function in tools/hv/hv kvp daemon.c. The vulnerability can be exploited locally.
Recommendations For hypervkvpd versions prior to 3.8-rc1, update to a version 3.8-rc1 or later to resolve the issue. For hypervkvpd-debuginfo-0, at the moment, there is no information about a newer version that contains a fix for this vulnerability. For Red Hat Enterprise Linux and CentOS, at the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, consider restricting access to the hv kvp daemon function in the tools/hv/hv kvp daemon.c file until a patch is available.
Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

BDU:2015-06669
BDU:2015-06670
BDU:2015-08909
BDU:2015-08910
CVE-2012-5532
OPENSUSE-SU-2024:10513-1
RHSA-2013:0807
RHSA-2013_0807
USN-1696-1
USN-1698-1
USN-1699-1
USN-1700-1
USN-1704-1
USN-1720-1
USN-1726-1

Affected Products

Centos
Red Hat
Hypervkvpd