CVE-2012-3417: Jan Kara Linux Diskquota

Medium severity, CVSS 4.0. EPSS: 3.1% chance of exploitation in the next 30 days.

The good_client function in rquotad (rquota_svc.c) in Linux DiskQuota (aka quota) before 3.17 invokes the hosts_ctl function the first time without a host name, which might allow remote attackers to bypass TCP Wrappers rules in hosts.deny.

Affected products

  • Jan Kara Linux Diskquota: up to and including 3.16; version 2.0 only; version 3.01 only; version 3.02 only; version 3.03 only; version 3.04 only; …

Published 2012-08-13. Last modified 2026-06-16.