PT-2013-5086 · Linux+3 · Linux Kernel+3

Petr Matousek

·

Published

2013-11-19

·

Updated

2023-02-13

·

CVE-2013-4591

CVSS v2.0

6.2

Medium

VectorAV:L/AC:H/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.7.2
Description The issue is related to a buffer overflow in the nfs4 get acl uncached function, which can cause a denial of service, resulting in memory corruption and system crash. It may also have other unspecified impacts. This occurs when a local user makes a getxattr system call for the system.nfs4 acl extended attribute of a pathname on an NFSv4 filesystem.
Recommendations For Linux kernel versions prior to 3.7.2, update to version 3.7.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the nfs4 get acl uncached function or limiting the use of the getxattr system call for the system.nfs4 acl extended attribute on NFSv4 filesystems until the update is applied.

Exploit

Fix

DoS

Buffer Overflow

Weakness Enumeration

Related Identifiers

CESA-2013_1645
CVE-2013-4591
RHSA-2013:1645
RHSA-2013_1645
RHSA-2014:0284
SUSE-SU-2015:0652-1

Affected Products

Centos
Linux Kernel
Red Hat
Suse