AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2018-12232

MEDIUM · CVSS 5.9 EPSS 6.61% Public Exploit

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2018-06-12 · Last synced 2026-08-04

CyberRota Analysis

AI analysis pending.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2018-12232
Severity
MEDIUM
CVSS
5.9
EPSS
6.61%
Linux

Original NVD Description

In net/socket.c in the Linux kernel through 4.17.1, there is a race condition between fchownat and close in cases where they target the same socket file descriptor, related to the sock_close and sockfs_setattr functions. fchownat does not increment the file descriptor reference count, which allows close to set the socket to NULL during fchownat's execution, leading to a NULL pointer dereference and system crash.