CVE-2012-2372
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
22/01/2013
Last modified:
11/04/2025
Description
The rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel 3.7.4 and earlier allows local users to cause a denial of service (BUG_ON and kernel panic) by establishing an RDS connection with the source IP address equal to the IPoIB interface's own IP address, as demonstrated by rds-ping.
Impact
Base Score 2.0
4.40
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | 3.7.4 (including) | |
| cpe:2.3:o:linux:linux_kernel:3.7:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:3.7.1:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:3.7.2:*:*:*:*:*:*:* | ||
| cpe:2.3:o:linux:linux_kernel:3.7.3:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://marc.info/?l=bugtraq&m=139447903326211&w=2
- http://rhn.redhat.com/errata/RHSA-2012-0743.html
- http://rhn.redhat.com/errata/RHSA-2012-1540.html
- http://ubuntu.com/usn/usn-1529-1
- http://www.securityfocus.com/bid/54062
- http://www.ubuntu.com/usn/USN-1555-1
- http://www.ubuntu.com/usn/USN-1556-1
- https://bugzilla.redhat.com/show_bug.cgi?id=822754
- https://oss.oracle.com/git/?p=redpatch.git%3Ba%3Dcommit%3Bh%3Dc7b6a0a1d8d636852be130fa15fa8be10d4704e8
- https://www.suse.com/support/update/announcement/2012/suse-su-20121679-1.html
- http://marc.info/?l=bugtraq&m=139447903326211&w=2
- http://rhn.redhat.com/errata/RHSA-2012-0743.html
- http://rhn.redhat.com/errata/RHSA-2012-1540.html
- http://ubuntu.com/usn/usn-1529-1
- http://www.securityfocus.com/bid/54062
- http://www.ubuntu.com/usn/USN-1555-1
- http://www.ubuntu.com/usn/USN-1556-1
- https://bugzilla.redhat.com/show_bug.cgi?id=822754
- https://oss.oracle.com/git/?p=redpatch.git%3Ba%3Dcommit%3Bh%3Dc7b6a0a1d8d636852be130fa15fa8be10d4704e8
- https://www.suse.com/support/update/announcement/2012/suse-su-20121679-1.html



