PT-2013-1025 · Linux+4 · Linux Kernel+4

Dave Jones

·

Published

2013-07-28

·

Updated

2023-02-13

·

CVE-2013-4162

CVSS v2.0

4.7

Medium

VectorAV:L/AC:M/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.10.3
Description The issue is related to the incorrect handling of pending data in the udp v6 push pending frames function in the IPv6 implementation. This can be exploited by local users through a crafted application that utilizes the UDP CORK option in a setsockopt system call, leading to a denial of service (BUG and system crash).
Recommendations For Linux kernel versions prior to 3.10.3, update to version 3.10.3 or later to resolve the issue. As a temporary workaround, consider avoiding the use of the UDP CORK option in setsockopt system calls until a patch is available.

Fix

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1003
BDU:2014-00090
CESA-2013_1436
CVE-2013-4162
DSA-2745-1
DSA-2906-1
MGASA-2013-0342
MGASA-2013-0343
MGASA-2013-0344
MGASA-2013-0345
MGASA-2013-0346
MGASA-2013-0371
MGASA-2013-0372
MGASA-2013-0373
MGASA-2013-0374
MGASA-2013-0375
RHSA-2013:1264
RHSA-2013:1292
RHSA-2013:1436
RHSA-2013:1520
RHSA-2013_1292
RHSA-2013_1436
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-1938-1
USN-1939-1
USN-1940-1
USN-1941-1
USN-1942-1
USN-1943-1
USN-1944-1
USN-1945-1
USN-1946-1
USN-1947-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse