PT-2013-5169 · Linux · Linux Kernel

Jonathan Salwan

·

Published

2013-11-12

·

Updated

2013-11-14

·

CVE-2013-4740

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions 3.x
Description The issue relies on user-space length values for kernel-memory copies of procfs file content, allowing attackers to gain privileges or cause a denial of service (memory corruption) via an application that provides crafted values.
Recommendations For Linux kernel version 3.x, consider restricting access to the goodix tool.c file in the Goodix gt915 touchscreen driver to minimize the risk of exploitation. As a temporary workaround, avoid using crafted user-space length values for kernel-memory copies of procfs file content until a patch is available.

Exploit

Fix

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2013-4740

Affected Products

Linux Kernel