CVE-2012-3520

Linux Kernel < 3.2.29 - Authentication Bypass

Title source: rule

Description

The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.

Scores

EPSS 0.0008
EPSS Percentile 24.6%

Classification

CWE
CWE-287
Status draft

Affected Products (50)

linux/linux_kernel < 3.2.29
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
linux/linux_kernel
... and 35 more

Timeline

Published Oct 03, 2012
Tracked Since Feb 18, 2026