PT-2013-1101 · Linux+2 · Linux Kernel+2
Theodore Tso
·
Published
2013-02-18
·
Updated
2023-02-13
·
CVE-2013-2015
CVSS v2.0
7.2
High
| Vector | AV:L/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 3.7.3
Description
The issue allows physically proximate attackers to cause a denial of service (system hang) via a crafted filesystem on removable media. This is due to the ext4 orphan del function in fs/ext4/namei.c not properly handling orphan-list entries for non-journal filesystems. Multiple vulnerabilities in the Linux package of the Debian GNU/Linux operating system can be exploited by a local attacker, potentially leading to breaches of confidentiality, integrity, and availability of protected information.
Recommendations
For Linux kernel versions prior to 3.7.3, update to version 3.7.3 or later to resolve the issue.
At the moment, there is no information about additional mitigation measures for other affected versions.
Fix
DoS
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Debian
Linux Kernel
Suse