PT-2013-3551 · Linux+2 · Linux Kernel+2

Prasad Pandit

·

Published

2013-06-07

·

Updated

2023-02-13

·

CVE-2013-2128

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.34
Description The issue is related to the tcp read sock function in the Linux kernel, which does not properly manage skb consumption. This allows local users to cause a denial of service, resulting in a system crash, by using a crafted splice system call for a TCP socket.
Recommendations For Linux kernel versions prior to 2.6.34, update to version 2.6.34 or later to resolve the issue.

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

CESA-2013_1051
CVE-2013-2128
RHSA-2013:1051
RHSA-2013:1080
RHSA-2013_1051

Affected Products

Centos
Linux Kernel
Red Hat