PT-2013-6316 · Linux+4 · Linux Kernel+4

Published

1970-01-01

·

Updated

2019-04-22

·

CVE-2013-4299

CVSS v2.0

6.0

Medium

VectorAV:N/AC:M/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 3.11.6
Description The issue is related to an interpretation conflict in the Linux kernel, specifically in the drivers/md/dm-snap-persistent.c file. This conflict allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block device. The vulnerability can be exploited remotely and may lead to a breach of confidentiality, integrity, and availability of protected information. Additionally, local users may gain access to sensitive kernel memory due to an error in the device-mapper subsystem.
Recommendations For Linux kernel versions through 3.11.6, update to a version later than 3.11.6 to resolve the issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability for other affected packages.

Exploit

Fix

Information Disclosure

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1003
ALT-PU-2013-1050
ALT-PU-2013-1051
ALT-PU-2013-1053
ALT-PU-2014-1422
BDU:2014-00091
BDU:2015-04307
BDU:2015-04308
BDU:2015-04309
BDU:2015-04310
CESA-2013_1436
CVE-2013-4299
DSA-2906-1
MGASA-2013-0371
MGASA-2013-0372
MGASA-2013-0373
MGASA-2013-0374
MGASA-2013-0375
RHSA-2013:1436
RHSA-2013:1449
RHSA-2013:1450
RHSA-2013:1490
RHSA-2013:1519
RHSA-2013:1520
RHSA-2013:1783
RHSA-2013:1860
RHSA-2013_1436
RHSA-2013_1449
RHSA-2013_1860
SUSE-RU-2015:0621-1
SUSE-SU-2014_1105-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2015-1
USN-2016-1
USN-2040-1
USN-2041-1
USN-2042-1
USN-2043-1
USN-2044-1
USN-2045-1
USN-2046-1
USN-2049-1
USN-2050-1
USN-2066-1
USN-2067-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse