CVE-2012-6657

Linux Kernel < 3.5.6 - Access Control

Title source: rule
STIX 2.1

Description

The sock_setsockopt function in net/core/sock.c in the Linux kernel before 3.5.7 does not ensure that a keepalive action is associated with a stream socket, which allows local users to cause a denial of service (system crash) by leveraging the ability to create a raw socket.

Scores

EPSS 0.0012
EPSS Percentile 30.9%

Details

CWE
CWE-264
Status published
Products (8)
linux/linux_kernel 3.5.1
linux/linux_kernel 3.5.2
linux/linux_kernel 3.5.3
linux/linux_kernel 3.5.4
linux/linux_kernel 3.5.5
linux/linux_kernel < 3.5.6
novell/suse_linux_enterprise_server 10.0 sp4
novell/suse_linux_enterprise_server 11.0 sp1
Published Sep 28, 2014
Tracked Since Feb 18, 2026