CVE-2012-2375 is a denial-of-service vulnerability affecting the Linux kernel's NFSv4 implementation, specifically in versions prior to 3.3.2. It stems from an incorrect length variable used during a copy operation within the __nfs4_get_acl_uncached function. This allows a malicious remote NFS server to trigger a system crash (OOPS) by sending an overly large number of bitmap words in an FATTR4_ACL reply. The vulnerability has a CVSS score of 4.6, indicating a medium severity. It requires adjacent network access (AV:A) and high attack complexity (AC:H), with no authentication needed (Au:N), leading to a complete denial of service (A:C) but no impact on confidentiality or integrity. There is no evidence of active exploitation, nor is there any known public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting low public attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 3.3.1CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
3.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.3:*:*:*:*:*:*:* | ||
3.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.3:rc1:*:*:*:*:*:* | ||
3.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.3:rc2:*:*:*:*:*:* | ||
3.3CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.3:rc3:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:H/Au:N/C:N/I:N/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.0 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.