Race condition in Linux kernel - CVE-2012-2373
Published: August 9, 2012 / Updated: August 11, 2020
Vulnerability details
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The Linux kernel before 3.4.5 on the x86 platform, when Physical Address Extension (PAE) is enabled, does not properly use the Page Middle Directory (PMD), which allows local users to cause a denial of service (panic) via a crafted application that triggers a race condition.
Affected software
SUSE Linux
How to mitigate CVE-2012-2373
External References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=26c191788f18129af0eb32a358cdaea0c7479626
- http://marc.info/?l=bugtraq&m=139447903326211&w=2
- http://rhn.redhat.com/errata/RHSA-2012-0743.html
- http://ubuntu.com/usn/usn-1529-1
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.5
- http://www.openwall.com/lists/oss-security/2012/05/18/11
- https://bugzilla.redhat.com/show_bug.cgi?id=822821
- https://github.com/torvalds/linux/commit/26c191788f18129af0eb32a358cdaea0c7479626