PT-2013-6317 · Linux+2 · Linux Kernel+2

Prasad Pandit

·

Published

1970-01-01

·

Updated

2016-12-31

·

CVE-2013-6382

CVSS v2.0

4.0

Medium

VectorAV:L/AC:H/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 3.12.1
Description The issue is related to multiple buffer underflows in the XFS implementation in the Linux kernel, allowing local users with CAP SYS ADMIN capability to cause a denial of service or possibly have other impacts by leveraging the XFS IOC ATTRLIST BY HANDLE or XFS IOC ATTRLIST BY HANDLE 32 ioctl call with a crafted length value. This is related to the xfs attrlist by handle function in fs/xfs/xfs ioctl.c and the xfs compat attrlist by handle function in fs/xfs/xfs ioctl32.c. Local users with CAP SYS ADMIN privileges may be able to elevate their privileges when using the XFS file system.
Recommendations For Linux kernel versions through 3.12.1, consider updating to a version that contains a fix for this issue. As a temporary workaround, consider restricting the use of the XFS IOC ATTRLIST BY HANDLE and XFS IOC ATTRLIST BY HANDLE 32 ioctl calls to minimize the risk of exploitation. Additionally, restrict access to the xfs attrlist by handle and xfs compat attrlist by handle functions until a patch is available.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1236
ALT-PU-2014-1422
ALT-PU-2014-1547
BDU:2014-00098
BDU:2015-04307
BDU:2015-04308
BDU:2015-04309
BDU:2015-04310
CVE-2013-6382
DSA-2906-1
MGASA-2013-0371
MGASA-2013-0373
MGASA-2013-0374
MGASA-2013-0375
MGASA-2014-0043
SUSE-RU-2015:0621-1
SUSE-SU-2014_0772-1
SUSE-SU-2014_0773-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2109-1
USN-2110-1
USN-2113-1
USN-2117-1
USN-2128-1
USN-2129-1
USN-2135-1
USN-2138-1
USN-2139-1
USN-2141-1
USN-2158-1

Affected Products

Alt Linux
Linux Kernel
Suse