PT-2013-3411 · Linux+3 · Linux Kernel+3

Mathias Krause

+2

·

Published

2013-03-07

·

Updated

2023-02-13

·

CVE-2013-1826

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.5.7
Description The issue is related to the xfrm state netlink function in the Linux kernel, which does not properly handle error conditions in dump one state function calls. This can be exploited by local users with the CAP NET ADMIN capability to gain privileges or cause a denial of service, resulting in a NULL pointer dereference and system crash.
Recommendations For Linux kernel versions prior to 3.5.7, update to version 3.5.7 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2013-1178
CESA-2013_0744
CVE-2013-1826
DSA-2668-1
RHSA-2013:0744
RHSA-2013:0747
RHSA-2013_0744
RHSA-2013_0747
USN-1644-1
USN-1645-1
USN-1646-1
USN-1647-1
USN-1648-1
USN-1649-1
USN-1652-1
USN-1824-1
USN-1829-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat