CVE-2012-2372

medium
Published 2013-01-22 · Modified 2026-04-29
CVSS v3
—
CVSS v4 NEW
—
not yet in upstream
VIR risk
4.4

Description

The rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel 3.7.4 and earlier allows local users to cause a denial of service (BUG_ON and kernel panic) by establishing an RDS connection with the source IP address equal to the IPoIB interface's own IP address, as demonstrated by rds-ping.

Predictions

Exploit likelihood
20%
Patch ETA
—

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker · View original ↗ · DFSG

CVE-2012-2372 NameCVE-2012-2372 DescriptionThe rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel 3.7.4 and earlier allows local users to cause a denial of service (BUG_ON and kernel panic) by establishing an RDS connection with the source IP address equal to the IPoIB interface's own IP address, as demonstrated by…

CVE-2012-2372

NameCVE-2012-2372
DescriptionThe rds_ib_xmit function in net/rds/ib_send.c in the Reliable Datagram Sockets (RDS) protocol implementation in the Linux kernel 3.7.4 and earlier allows local users to cause a denial of service (BUG_ON and kernel panic) by establishing an RDS connection with the source IP address equal to the IPoIB interface's own IP address, as demonstrated by rds-ping.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)bullseye5.10.223-1fixed
bullseye (security)5.10.257-1fixed
bookworm6.1.170-3fixed
bookworm (security)6.1.172-1fixed
trixie6.12.86-1fixed
trixie (security)6.12.90-1fixed
forky7.0.9-1fixed
sid7.0.10-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcewheezy3.2.53-1
linuxsource(unstable)3.11.10-1unimportant

Notes

rds is not included in distributed kernel images, only marked as "experimental"

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
rds is not included in distributed kernel images, only marked as "experimental"

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.11.10-1
debian debianbullseyefixed3.11.10-1
debian debianforkyfixed3.11.10-1
debian debiansidfixed3.11.10-1
debian debiantrixiefixed3.11.10-1
linux linux-kernelaffected
linux linux-kernel3.7affected
linux linux-kernel3.7.1affected
linux linux-kernel3.7.2affected
linux linux-kernel3.7.3affected

References

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.