Your submission was sent successfully! Close

You have successfully unsubscribed! Close

CVE-2012-0810

Published: 12 February 2020

The int3 handler in the Linux kernel before 3.3 relies on a per-CPU debug stack, which allows local users to cause a denial of service (stack corruption and panic) via a crafted application that triggers certain lock contention. If there is contention on this lock then the task may schedule out. As the task is using a per CPU stack, and another task may come in and use the same stack, the stack can become corrupted and cause the kernel to panic.

Priority

Low

Cvss 3 Severity Score

5.5

Score breakdown

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
hardy Ignored
(PREEMPT_RT_FULL not configured)
lucid Ignored
(PREEMPT_RT_FULL not configured)
maverick Ignored
(PREEMPT_RT_FULL not configured)
natty Ignored
(PREEMPT_RT_FULL not configured)
oneiric Ignored
(PREEMPT_RT_FULL not configured)
upstream Ignored
(PREEMPT_RT_FULL not configured)
linux-ec2
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Ignored
(PREEMPT_RT_FULL not configured)
maverick Ignored
(binary supplied by "linux" now)
natty Does not exist

oneiric Does not exist

upstream Ignored
(PREEMPT_RT_FULL not configured)
linux-fsl-imx51
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Ignored
(PREEMPT_RT_FULL not configured)
maverick Does not exist

natty Does not exist

oneiric Does not exist

upstream Ignored
(PREEMPT_RT_FULL not configured)
linux-lts-backport-maverick
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Ignored
(PREEMPT_RT_FULL not configured)
maverick Does not exist

natty Does not exist

oneiric Does not exist

upstream Ignored
(PREEMPT_RT_FULL not configured)
linux-lts-backport-natty
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Ignored
(PREEMPT_RT_FULL not configured)
maverick Does not exist

natty Does not exist

oneiric Does not exist

upstream Ignored
(PREEMPT_RT_FULL not configured)
linux-lts-backport-oneiric
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Ignored
(PREEMPT_RT_FULL not configured)
maverick Does not exist

natty Does not exist

oneiric Does not exist

upstream Ignored
(PREEMPT_RT_FULL not configured)
linux-mvl-dove
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Ignored
(reached end-of-life)
maverick Ignored
(PREEMPT_RT_FULL not configured)
natty Does not exist

oneiric Does not exist

upstream Ignored
(PREEMPT_RT_FULL not configured)
linux-ti-omap4
Launchpad, Ubuntu, Debian
hardy Does not exist

lucid Does not exist

maverick Ignored
(PREEMPT_RT_FULL not configured)
natty Ignored
(PREEMPT_RT_FULL not configured)
oneiric Ignored
(PREEMPT_RT_FULL not configured)
upstream Ignored
(PREEMPT_RT_FULL not configured)

Severity score breakdown

Parameter Value
Base score 5.5
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Scope Unchanged
Confidentiality None
Integrity impact None
Availability impact High
Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H