PT-2012-4169 · Linux+1 · Linux Kernel+1

Florian Weimer

·

Published

2012-07-03

·

Updated

2024-06-15

·

CVE-2012-2669

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.4.5
Description The issue concerns a lack of validation for the origin of Netlink messages in the main function of tools/hv/hv kvp daemon.c in hypervkvpd. This allows local users to spoof Netlink communication by sending a crafted connector message.
Recommendations For versions prior to 3.4.5, update to version 3.4.5 or later to resolve the issue.

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2012-2669
OPENSUSE-SU-2024:10513-1
SUSE-SU-2012_0817-1
USN-1514-1
USN-1529-1
USN-1719-1
USN-1720-1
USN-1726-1

Affected Products

Linux Kernel
Suse