CVE-2012-3375

Linux Kernel < 3.2.23 - Denial of Service

Title source: rule

Description

The epoll_ctl system call in fs/eventpoll.c in the Linux kernel before 3.2.24 does not properly handle ELOOP errors in EPOLL_CTL_ADD operations, which allows local users to cause a denial of service (file-descriptor consumption and system crash) via a crafted application that attempts to create a circular epoll dependency. NOTE: this vulnerability exists because of an incorrect fix for CVE-2011-1083.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Yurij M. Plotnikov · cdoslinux
https://www.exploit-db.com/exploits/19605

Scores

EPSS 0.0014
EPSS Percentile 33.3%

Details

Status published
Products (50)
linux/linux_kernel 3.0.1
linux/linux_kernel 3.0.2
linux/linux_kernel 3.0.3
linux/linux_kernel 3.0.4
linux/linux_kernel 3.0.5
linux/linux_kernel 3.0.6
linux/linux_kernel 3.0.7
linux/linux_kernel 3.0.8
linux/linux_kernel 3.0.9
linux/linux_kernel 3.0.10
... and 40 more
Published Oct 03, 2012
Tracked Since Feb 18, 2026