PT-2012-6296 · Linux+2 · Linux Kernel+2

Florian Weimer

·

Published

2012-12-31

·

Updated

2023-01-20

·

CVE-2012-6689

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.5.5
Description The issue concerns the netlink sendmsg function in the Linux kernel, which fails to validate the dst pid field. This allows local users to potentially spoof Netlink messages, although the exact impact is not specified.
Recommendations For Linux kernel versions prior to 3.5.5, update to version 3.5.5 or later to resolve the issue.

Exploit

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CESA-2014_1392
CVE-2012-6689
DLA-246-1
RHSA-2014:1392
RHSA-2014_1392
USN-1599-1
USN-1610-1

Affected Products

Centos
Linux Kernel
Red Hat