PT-2013-1031 · Linux+3 · Linux Kernel+3

Fabian Yamaguchi

+1

·

Published

2013-11-26

·

Updated

2024-04-26

·

CVE-2013-6381

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.12.1
Description The issue allows local users to cause a denial of service or possibly have unspecified other impact via an SNMP ioctl call with a length value that is incompatible with the command-buffer size. This is due to a buffer overflow in the qeth snmp command function in drivers/s390/net/qeth core main.c. The ioctl call IOC QETH ADP SET SNMP CONTROL is involved in the system call.
Recommendations For Linux kernel versions prior to 3.12.1, update to version 3.12.1 or later to resolve the issue. As a temporary workaround, consider restricting access to the qeth snmp command function until a patch is available. Avoid using the IOC QETH ADP SET SNMP CONTROL ioctl call with incompatible length values in the command-buffer size until the issue is resolved.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1236
ALT-PU-2014-1422
AZL-34238
AZL-34847
BDU:2014-00097
CESA-2014_0159
CVE-2013-6381
DSA-2906-1
MGASA-2013-0371
MGASA-2013-0372
MGASA-2013-0373
MGASA-2013-0374
MGASA-2013-0375
RHSA-2014:0159
RHSA-2014:0284
RHSA-2014:0285
RHSA-2014:0476
RHSA-2014_0159
RHSA-2014_0285

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat