Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2012-2127 Details

Description

fs/proc/root.c in the procfs implementation in the Linux kernel before 3.2 does not properly interact with CLONE_NEWPID clone system calls, which allows remote attackers to cause a denial of service (reference leak and memory consumption) by making many connections to a daemon that uses PID namespaces to isolate clients, as demonstrated by vsftpd.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=905ad269c55fc62bee3da29f7b1d1efeba8aa1e1 CVE
https://bugzilla.novell.com/show_bug.cgi?id=757783 CVEExploit
https://bugzilla.redhat.com/show_bug.cgi?id=815188 CVEExploit
https://github.com/torvalds/linux/commit/905ad269c55fc62bee3da29f7b1d1efeba8aa1e1 CVEExploitPatch
http://ubuntu.com/usn/usn-1607-1 CVE

see all 22 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer[email protected]

Affected Products

ProductVersions
linux linux kernel
<= 3.1.10
3.1.1
3.1.2
3.1.3
3.1.4

CPE

  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:3.1.1:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:3.1.2:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:3.1.3:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:3.1.4:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:3.1.5:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:3.1.6:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:3.1.7:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:3.1.8:*:*:*:*:*:*:*
  • cpe:2.3:o:linux:linux_kernel:3.1.9:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

6 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2012-2127
NVD Published Date:
Jun 21, 2012
NVD Last Modified:
Jun 16, 2026
Source:
[email protected]
CVE-2012-2127 Details - Not Deferred