CVE-2012-5375

Linux kernel < 3.8 - Denial of Service via Btrfs CRC32C Hash Collision

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-5375. PoCs published by Pascal Junod.

AI-analyzed exploit summary This exploit leverages a CRC32 collision vulnerability in the Linux kernel to trigger an infinite loop, causing a local denial-of-service (DoS). The code generates malformed filenames with forged CRC32 values to exploit the flaw.

Description

The CRC32C feature in the Btrfs implementation in the Linux kernel before 3.8-rc1 allows local users to cause a denial of service (prevention of file creation) by leveraging the ability to write to a directory important to the victim, and creating a file with a crafted name that is associated with a specific CRC32C hash value.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Pascal Junod · pythondoslinux
https://www.exploit-db.com/exploits/38132

This exploit leverages a CRC32 collision vulnerability in the Linux kernel to trigger an infinite loop, causing a local denial-of-service (DoS). The code generates malformed filenames with forged CRC32 values to exploit the flaw.

Classification
Working Poc 90%
Attack Type
Dos
Complexity
Moderate
Reliability
Reliable
Target: Linux kernel (versions affected by CVE-2012-5375)
No auth needed
Prerequisites: Local access to the target system
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (10)

Core 10
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2017-1
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1947-1
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1944-1
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1945-1
Mailing List mailing-list x_refsource_mlist
http://openwall.com/lists/oss-security/2012/12/13/20
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1946-1

Scores

EPSS 0.0086
EPSS Percentile 53.9%

Details

CWE
CWE-310
Status published
Products (44)
linux/linux_kernel 3.0 rc1 (7 CPE variants)
linux/linux_kernel 3.0.1
linux/linux_kernel 3.0.2
linux/linux_kernel 3.0.3
linux/linux_kernel 3.0.4
linux/linux_kernel 3.0.5
linux/linux_kernel 3.0.6
linux/linux_kernel 3.0.7
linux/linux_kernel 3.0.8
linux/linux_kernel 3.0.9
... and 34 more
Published Feb 18, 2013
Tracked Since Feb 18, 2026