PT-2012-5415 · Linux · Linux Kernel

Mikulas Patocka

·

Published

2012-10-10

·

Updated

2023-02-13

·

CVE-2012-4467

CVSS v2.0

6.6

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.5.4
Description The issue affects the Linux kernel, where the do siocgstamp and do siocgstampns functions in net/socket.c use an incorrect argument order. This allows local users to obtain sensitive information from kernel memory or cause a denial of service, resulting in a system crash, via a crafted ioctl call.
Recommendations For Linux kernel versions prior to 3.5.4, update to version 3.5.4 or later to resolve the issue.

Exploit

Fix

Weakness Enumeration

Related Identifiers

CVE-2012-4467

Affected Products

Linux Kernel