CVE-2012-3520

low
Published 2012-10-03 · Modified 2026-04-29
CVSS v3
CVSS v2
1.9
VIR risk
1.9

Description

The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2012-3520

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.2.29-1
debian debianbullseyefixed3.2.29-1
debian debianforkyfixed3.2.29-1
debian debiansidfixed3.2.29-1
debian debiantrixiefixed3.2.29-1
linux linux-kernelaffected
linux linux-kernel2.3.2affected
linux linux-kernel2.3.20affected
linux linux-kernel2.3.21affected
linux linux-kernel2.3.22affected
linux linux-kernel2.3.23affected
linux linux-kernel2.3.24affected
linux linux-kernel2.3.25affected
linux linux-kernel2.3.26affected
linux linux-kernel2.3.27affected
linux linux-kernel2.3.28affected
linux linux-kernel2.3.29affected
linux linux-kernel2.4.33.2affected
linux linux-kernel2.6.13.2affected
linux linux-kernel2.6.23.2affected
linux linux-kernel2.6.33.2affected
linux linux-kernel2.6.33.20affected
linux linux-kernel3.2affected
linux linux-kernel3.2.1affected
linux linux-kernel3.2.2affected
linux linux-kernel3.2.3affected
linux linux-kernel3.2.4affected
linux linux-kernel3.2.5affected
linux linux-kernel3.2.6affected
linux linux-kernel3.2.7affected
linux linux-kernel3.2.8affected
linux linux-kernel3.2.9affected
linux linux-kernel3.2.10affected
linux linux-kernel3.2.11affected
linux linux-kernel3.2.12affected
linux linux-kernel3.2.13affected
linux linux-kernel3.2.14affected
linux linux-kernel3.2.15affected
linux linux-kernel3.2.16affected
linux linux-kernel3.2.17affected
linux linux-kernel3.2.18affected
linux linux-kernel3.2.19affected
linux linux-kernel3.2.20affected
linux linux-kernel3.2.21affected
linux linux-kernel3.2.22affected
linux linux-kernel3.2.23affected
linux linux-kernel3.2.24affected
linux linux-kernel3.2.25affected
linux linux-kernel3.2.26affected
linux linux-kernel3.2.27affected
linux linux-kernel3.2.28affected
linux linux-kernel3.3.2affected

References

CWEs

CWE-287

Verify integrity in audit chain (admin only). AS-IS.