CVE-2012-3412
HIGH severity · CVSS 7.8 · CWE-189
7.8CVSS HIGH
Summary
The sfc (aka Solarflare Solarstorm) driver in the Linux kernel before 3.2.30 allows remote attackers to cause a denial of service (DMA descriptor consumption and network-controller outage) via crafted TCP packets that trigger a small MSS value.
Impact & exploitability
Attack vectorNetwork
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)6%
AV:N/AC:L/Au:N/C:N/I:N/A:C
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://lists.opensuse.org/opensuse-security-announce/2012-10/msg00005.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2012-1323.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2012-1324.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2012-1347.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2012-1375.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2012-1401.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2012-1430.htmlAdvisory
- http://secunia.com/advisories/50633