PT-2014-1022 · Linux+4 · Linux Kernel+4

Mpb

·

Published

2013-12-09

·

Updated

2017-12-16

·

CVE-2013-7265

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.12.4
Description The issue allows local users to obtain sensitive information from kernel stack memory. This is due to the pn recvmsg function updating a certain length value before ensuring that an associated data structure has been initialized. The sensitive information can be accessed via system calls such as recvfrom, recvmmsg, or recvmsg.
Recommendations For Linux kernel versions prior to 3.12.4, update to version 3.12.4 or later to resolve the issue. As a temporary workaround, consider restricting the use of the pn recvmsg function until a patch is available. Additionally, restrict access to the recvmmsg and recvmsg system calls to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1264
ALT-PU-2014-1422
BDU:2014-00100
CESA-2014_0159
CVE-2013-7265
DSA-2906-1
OPENSUSE-SU-2014_0678-1
RHSA-2014:0159
RHSA-2014:0439
RHSA-2014_0159
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2107-1
USN-2108-1
USN-2109-1
USN-2110-1
USN-2113-1
USN-2117-1
USN-2135-1
USN-2136-1
USN-2138-1
USN-2139-1
USN-2141-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse