# CVE-2012-0038 — Linux Kernel

> As of 2024-08-06, CVE-2012-0038 is a MEDIUM-severity vulnerability in Linux Kernel, CVSS v3.1 5.5, EPSS 0.3% (32.6th percentile). Threadlinqs Intelligence links 1 tracked threat campaign to CVE-2012-0038, most recently “UT Dallas Study: Multi-Patch CVE Fixes Leave Open Source Exposed to N-Day Exploitation Windows”.

**Last updated:** 2024-08-06

## What is CVE-2012-0038?

Integer overflow in the xfs_acl_from_disk function in fs/xfs/xfs_acl.c in the Linux kernel before 3.1.9 allows local users to cause a denial of service (panic) via a filesystem with a malformed ACL, leading to a heap-based buffer overflow.

The record classifies CVE-2012-0038 under weakness class [CWE-190](https://intel.threadlinqs.com/cwe/CWE-190). Its CVSS v3 base vector states that the flaw requires local access to the host, needs low-privilege credentials, needs no user interaction, and has high impact on availability. 1 affected-product entry is recorded, across 1 vendor, listed below. The identifier was first published 5254 days ago.

## Severity and exploitation probability

- **CVSS v3.1 base score:** 5.5 — MEDIUM (`CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H`)
- **EPSS (FIRST):** 0.3% probability of exploitation in the next 30 days, higher than 32.6% of all scored CVEs
- **CISA KEV:** Not listed in the CISA Known Exploited Vulnerabilities catalog
- **Threadlinqs priority:** 4.1/10 — a Threadlinqs composite of the CVSS base score, the EPSS percentile and public exploit availability
- **Published:** 2012-05-17, last modified 2024-08-06

## Is CVE-2012-0038 being exploited?

No public exploitation evidence for CVE-2012-0038 is recorded in the sources Threadlinqs tracks — CISA KEV, Exploit-DB, public proof-of-concept repositories and ProjectDiscovery Nuclei — as of 2024-08-06. That is an absence of evidence in those feeds, not a guarantee that the vulnerability is unexploited.

## Affected products and versions

- [Linux](https://intel.threadlinqs.com/vendors/linux): Kernel

## How to fix CVE-2012-0038

The record marks a vendor fix as available for CVE-2012-0038. Patch reference: [http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1.9](http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1.9). Vendor advisory: [http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1.9](http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1.9). Apply the vendor fix referenced above to every affected product listed in this record, then confirm the running version against the vendor advisory.

## Threat activity tracking CVE-2012-0038

1 tracked threat in the Threadlinqs corpus references CVE-2012-0038, either in the campaign’s CVE list or as an indicator on the campaign record.

- [UT Dallas Study: Multi-Patch CVE Fixes Leave Open Source Exposed to N-Day Exploitation Windows](https://intel.threadlinqs.com/threat/TL-2026-1704) — MEDIUM · 2026-07-26

## Sources

Enriched from CVE.org, NVD, FIRST EPSS, GitHub Security Advisories. Last verified by Threadlinqs on 2026-07-27. This product uses the NVD API but is not endorsed or certified by the NVD.

**Vendor advisory and patch**

- [github.com](https://github.com/torvalds/linux/commit/fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba)
- [git.kernel.org](http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fa8b18edd752a8b4e9d1ee2cd615b82c93cf8bba)
- [git.kernel.org](http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=093019cf1b18dd31b2c3b77acce4e000e2cbc9ce)
- [bugzilla.redhat.com](https://bugzilla.redhat.com/show_bug.cgi?id=773280)
- [github.com (093019cf1b18dd31b2c3b77acce4e000e2cbc9ce)](https://github.com/torvalds/linux/commit/093019cf1b18dd31b2c3b77acce4e000e2cbc9ce)

**Mailing list and disclosure**

- [openwall.com — mailing list](http://www.openwall.com/lists/oss-security/2012/01/10/11)

_Showing 6 of 7 recorded references._

Canonical: https://intel.threadlinqs.com/cve/CVE-2012-0038
Full detection coverage and IOCs for threats exploiting CVE-2012-0038 via the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp
