PT-2013-4919 · Linux+1 · Linux Kernel+1

Vince Weaver

·

Published

2013-08-24

·

Updated

2023-02-13

·

CVE-2013-4254

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.10.8
Description The issue allows local users to gain privileges or cause a denial of service, resulting in a system crash due to a NULL pointer dereference. This is achieved by adding a hardware event to an event group led by a software event through the validate event function in arch/arm/kernel/perf event.c on the ARM platform.
Recommendations For Linux kernel versions prior to 3.10.8, update to version 3.10.8 or later to resolve the issue. As a temporary workaround, consider restricting access to the validate event function in arch/arm/kernel/perf event.c to minimize the risk of exploitation. Avoid adding hardware events to event groups led by software events until the issue is resolved.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2013-4254
MGASA-2013-0342
MGASA-2013-0343
MGASA-2013-0344
MGASA-2013-0345
MGASA-2013-0346
MGASA-2013-0371
MGASA-2013-0372
MGASA-2013-0373
MGASA-2013-0374
MGASA-2013-0375
OPENSUSE-SU-2014_0677-1
USN-1968-1
USN-1969-1
USN-1970-1
USN-1971-1
USN-1972-1
USN-1973-1
USN-1974-1
USN-1975-1

Affected Products

Linux Kernel
Suse