CVE-2012-6638: Linux Kernel
High severity, CVSS 7.8. EPSS: 3.3% chance of exploitation in the next 30 days.
The tcp_rcv_state_process function in net/ipv4/tcp_input.c in the Linux kernel before 3.2.24 allows remote attackers to cause a denial of service (kernel resource consumption) via a flood of SYN+FIN TCP packets, a different vulnerability than CVE-2012-2663.
Affected products
- Linux Linux Kernel: before 3.0.38 (fixed in 3.0.38); from 3.1, before 3.2.24 (fixed in 3.2.24)
Published 2014-02-15. Last modified 2026-06-16.