PT-2014-3383 · Linux+1 · Linux Kernel+1

Published

2013-12-09

·

Updated

2014-04-02

·

CVE-2013-7348

CVSS v2.0

4.6

Medium

VectorAV:L/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.12.4
Description A double free vulnerability exists in the ioctx alloc function in fs/aio.c, allowing local users to cause a denial of service, potentially leading to a system crash, or possibly having other unspecified impacts. This issue is triggered by vectors involving an error condition in the aio setup ring function.
Recommendations For versions prior to 3.12.4, update to version 3.12.4 or later to resolve the issue.

Exploit

Fix

DoS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2013-1264
ALT-PU-2014-1422
CVE-2013-7348

Affected Products

Alt Linux
Linux Kernel