CVE-2012-3520: Linux Kernel
Low severity, CVSS 1.9. EPSS: 0.4% chance of exploitation in the next 30 days.
The Netlink implementation in the Linux kernel before 3.2.30 does not properly handle messages that lack SCM_CREDENTIALS data, which might allow local users to spoof Netlink communication via a crafted message, as demonstrated by a message to (1) Avahi or (2) NetworkManager.
Affected products
- Linux Linux Kernel: up to and including 3.2.29; version 2.3.2 only; version 2.3.20 only; version 2.3.21 only; version 2.3.22 only; version 2.3.23 only; …
Published 2012-10-03. Last modified 2026-06-16.