CVE-2012-2123: Linux Kernel
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
The cap_bprm_set_creds function in security/commoncap.c in the Linux kernel before 3.3.3 does not properly handle the use of file system capabilities (aka fcaps) for implementing a privileged executable file, which allows local users to bypass intended personality restrictions via a crafted application, as demonstrated by an attack that uses a parent process to disable ASLR.
Affected products
- Linux Linux Kernel: before 3.0.29 (fixed in 3.0.29); from 3.1, before 3.2.16 (fixed in 3.2.16); from 3.3, before 3.3.3 (fixed in 3.3.3)
Published 2012-05-17. Last modified 2026-06-16.