PT-2013-4008 · Linux+4 · Linux Kernel+4

Kees Cook

·

Published

2013-09-13

·

Updated

2014-04-24

·

CVE-2013-2888

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.11
Description The issue is related to multiple array index errors in the Human Interface Device (HID) subsystem, specifically in the drivers/hid/hid-core.c file. This allows physically proximate attackers to potentially execute arbitrary code or cause a denial of service due to heap memory corruption. The attack can be initiated via a crafted device that provides an invalid Report ID.
Recommendations For Linux kernel versions prior to 3.11, update to a version 3.11 or later to resolve the issue.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1178
ALT-PU-2014-1422
CESA-2013_1645
CVE-2013-2888
DSA-2766-1
MGASA-2013-0342
MGASA-2013-0343
MGASA-2013-0344
MGASA-2013-0345
MGASA-2013-0346
MGASA-2013-0371
MGASA-2013-0372
MGASA-2013-0373
MGASA-2013-0374
MGASA-2013-0375
RHSA-2013:1490
RHSA-2013:1527
RHSA-2013:1645
RHSA-2013_1645
RHSA-2014:0433
RHSA-2014_0433
SUSE-SU-2015:0652-1
USN-1976-1
USN-1977-1
USN-1995-1
USN-1998-1
USN-2019-1
USN-2021-1
USN-2022-1
USN-2024-1
USN-2038-1
USN-2039-1
USN-2050-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse