4.9

CVE-2012-6657

Exploit

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.

Data is provided by the National Vulnerability Database (NVD)
LinuxLinux Kernel Version <= 3.5.6
LinuxLinux Kernel Version3.5.1
LinuxLinux Kernel Version3.5.2
LinuxLinux Kernel Version3.5.3
LinuxLinux Kernel Version3.5.4
LinuxLinux Kernel Version3.5.5
NovellSuse Linux Enterprise Server Version10.0 Updatesp4 SwEditionltss
NovellSuse Linux Enterprise Server Version11.0 Updatesp1 SwEditionltss
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.12% 0.281
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C