CVE-2012-5374
Linux Kernel - Denial of Service via Btrfs CRC32C Hash Collision
Title source: llmDescription
The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (extended runtime of kernel code) by creating many different files whose names are associated with the same CRC32C hash value.
References (11)
Core 11
Core References
Various Sources x_refsource_misc
http://crypto.junod.info/2012/12/13/hash-dos-and-btrfs/
Patch x_refsource_confirm
http://www.kernel.org/pub/linux/kernel/v3.x/testing/patch-3.8-rc1.bz2
Exploit, Patch x_refsource_confirm
https://github.com/torvalds/linux/commit/9c52057c698fb96f8f07e7a4bcf4801a092bda89
Patch x_refsource_confirm
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9c52057c698fb96f8f07e7a4bcf4801a092bda89
Mailing List vendor-advisory
x_refsource_suse
http://lists.opensuse.org/opensuse-security-announce/2013-03/msg00004.html
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1944-1
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1945-1
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2017-1
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1947-1
Mailing List mailing-list
x_refsource_mlist
http://openwall.com/lists/oss-security/2012/12/13/20
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1946-1
Scores
EPSS
0.0048
EPSS Percentile
38.9%
Details
CWE
CWE-310
Status
published
Products (44)
linux/linux_kernel
3.0 rc1 (7 CPE variants)
linux/linux_kernel
3.0.1
linux/linux_kernel
3.0.2
linux/linux_kernel
3.0.3
linux/linux_kernel
3.0.4
linux/linux_kernel
3.0.5
linux/linux_kernel
3.0.6
linux/linux_kernel
3.0.7
linux/linux_kernel
3.0.8
linux/linux_kernel
3.0.9
... and 34 more
Published
Feb 18, 2013
Tracked Since
Feb 18, 2026