Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2013-1826

Overview

Vulnerability Score 6.2 6.2
CVE Id CVE-2013-1826
Last Modified 04 Jun 2013 11:42:36
Published 22 Mar 2013 07:59:11
Confidentiality Impact COMPLETE COMPLETE
Integrity Impact COMPLETE COMPLETE
Availability Impact COMPLETE COMPLETE
Access Vector LOCAL
Access Complexity HIGH
Authentication NONE

CVE-2013-1826

Summary

The xfrm_state_netlink function in net/xfrm/xfrm_user.c in the Linux kernel before 3.5.7 does not properly handle error conditions in dump_one_state function calls, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability.

Vulnerable Systems

Operating System

  • Linux Kernel 3.5.1

  • Linux Kernel 3.5.2

  • Linux Kernel 3.5.3

  • Linux Kernel 3.5.4

  • Linux Kernel 3.5.5

  • Linux Kernel 3.5.6


References

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=864745d291b5ba80ea0bd0edcbe67273de368836

CONFIRM - https://github.com/torvalds/linux/commit/864745d291b5ba80ea0bd0edcbe67273de368836

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=919384

MLIST - [oss-security] 20130307 Re: CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs

CONFIRM - http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.7

UBUNTU - USN-1829-1

REDHAT - RHSA-2013:0744


Last Updated: 27 May 2016 11:02:07