ALT-PU-2014-1383-1
Package kernel-image-el-def updated to version 2.6.32-alt18 for branch c7 in task 117041.
Closed vulnerabilities
BDU:2014-00071
Уязвимость операционной системы Linux, позволяющая злоумышленнику получить доступ к конфиденциальной информации из памяти ядра
BDU:2014-00075
Уязвимость операционной системы Linux, позволяющая злоумышленнику получить доступ к конфиденциальной информации из стековой памяти ядра
BDU:2014-00078
Уязвимость операционной системы Linux, позволяющая злоумышленнику получить доступ к конфиденциальной информации из стековой памяти ядра
BDU:2014-00079
Уязвимость операционной системы Linux, позволяющая злоумышленнику получить доступ к конфиденциальной информации из стековой памяти ядра
BDU:2014-00080
Уязвимость операционной системы Linux, позволяющая злоумышленнику получить доступ к конфиденциальной информации из стековой памяти ядра
BDU:2014-00085
Уязвимость операционной системы Linux, позволяющая злоумышленнику осуществить доступ к защищаемой информации или вызвать отказ в обслуживании
BDU:2014-00087
Уязвимость операционной системы Linux, позволяющая злоумышленнику вызвать локальный отказ в обслуживании
BDU:2014-00089
Уязвимость операционной системы Linux, приводящая к раскрытию информации
BDU:2014-00090
Уязвимость операционной системы Linux, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00091
Уязвимость операционной системы Linux, позволяющая злоумышленнику получить доступ к конфиденциальной информации из памяти ядра
BDU:2014-00092
Уязвимость операционной системы Linux, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2014-00095
Уязвимость операционной системы Linux, позволяющая злоумышленнику вызвать отказ в обслуживании
BDU:2015-03064
Уязвимости операционной системы Debian GNU/Linux, позволяющие локальному злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
BDU:2015-04307
Уязвимости операционной системы SUSE Linux Enterprise, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
- CVE-2012-2372
- CVE-2013-2929
- CVE-2013-4299
- CVE-2013-4579
- CVE-2013-6382
- CVE-2013-7339
- CVE-2014-0055
- CVE-2014-0077
- CVE-2014-0101
- CVE-2014-0131
- CVE-2014-0155
- CVE-2014-1444
- CVE-2014-1445
- CVE-2014-1446
- CVE-2014-1874
- CVE-2014-2309
- CVE-2014-2523
- CVE-2014-2678
- CVE-2014-2851
- CVE-2014-3122
- CVE-2014-3144
- CVE-2014-3145
- CVE-2014-3917
- CVE-2014-4652
- CVE-2014-4653
- CVE-2014-4654
- CVE-2014-4655
- CVE-2014-4656
- CVE-2014-4699
BDU:2015-04308
Уязвимости операционной системы SUSE Linux Enterprise, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
- CVE-2012-2372
- CVE-2013-2929
- CVE-2013-4299
- CVE-2013-4579
- CVE-2013-6382
- CVE-2013-7339
- CVE-2014-0055
- CVE-2014-0077
- CVE-2014-0101
- CVE-2014-0131
- CVE-2014-0155
- CVE-2014-1444
- CVE-2014-1445
- CVE-2014-1446
- CVE-2014-1874
- CVE-2014-2309
- CVE-2014-2523
- CVE-2014-2678
- CVE-2014-2851
- CVE-2014-3122
- CVE-2014-3144
- CVE-2014-3145
- CVE-2014-3917
- CVE-2014-4652
- CVE-2014-4653
- CVE-2014-4654
- CVE-2014-4655
- CVE-2014-4656
- CVE-2014-4699
BDU:2015-04309
Уязвимости операционной системы SUSE Linux Enterprise, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
- CVE-2012-2372
- CVE-2013-2929
- CVE-2013-4299
- CVE-2013-4579
- CVE-2013-6382
- CVE-2013-7339
- CVE-2014-0055
- CVE-2014-0077
- CVE-2014-0101
- CVE-2014-0131
- CVE-2014-0155
- CVE-2014-1444
- CVE-2014-1445
- CVE-2014-1446
- CVE-2014-1874
- CVE-2014-2309
- CVE-2014-2523
- CVE-2014-2678
- CVE-2014-2851
- CVE-2014-3122
- CVE-2014-3144
- CVE-2014-3145
- CVE-2014-3917
- CVE-2014-4652
- CVE-2014-4653
- CVE-2014-4654
- CVE-2014-4655
- CVE-2014-4656
- CVE-2014-4699
BDU:2015-04310
Уязвимости операционной системы SUSE Linux Enterprise, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
- CVE-2012-2372
- CVE-2013-2929
- CVE-2013-4299
- CVE-2013-4579
- CVE-2013-6382
- CVE-2013-7339
- CVE-2014-0055
- CVE-2014-0077
- CVE-2014-0101
- CVE-2014-0131
- CVE-2014-0155
- CVE-2014-1444
- CVE-2014-1445
- CVE-2014-1446
- CVE-2014-1874
- CVE-2014-2309
- CVE-2014-2523
- CVE-2014-2678
- CVE-2014-2851
- CVE-2014-3122
- CVE-2014-3144
- CVE-2014-3145
- CVE-2014-3917
- CVE-2014-4652
- CVE-2014-4653
- CVE-2014-4654
- CVE-2014-4655
- CVE-2014-4656
- CVE-2014-4699
BDU:2015-05303
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05304
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05305
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05306
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05307
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05308
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05309
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05310
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05311
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05312
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05313
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05314
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05315
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить доступность защищаемой информации
BDU:2015-05542
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
BDU:2015-05543
Уязвимости операционной системы openSUSE, позволяющие злоумышленнику нарушить конфиденциальность, целостность и доступность защищаемой информации
Modified: 2024-11-21
CVE-2012-6537
net/xfrm/xfrm_user.c in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1f86840f897717f86d523a13e99a447e6a5d2fa5
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1f86840f897717f86d523a13e99a447e6a5d2fa5
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7b789836f434c87168eab067cfbed1ec4783dffd
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7b789836f434c87168eab067cfbed1ec4783dffd
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f778a636713a435d3a922c60b1622a91136560c1
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f778a636713a435d3a922c60b1622a91136560c1
- RHSA-2013:0744
- RHSA-2013:0744
- [oss-security] 20130305 CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- [oss-security] 20130305 CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- USN-1792-1
- USN-1792-1
- USN-1798-1
- USN-1798-1
- https://github.com/torvalds/linux/commit/1f86840f897717f86d523a13e99a447e6a5d2fa5
- https://github.com/torvalds/linux/commit/1f86840f897717f86d523a13e99a447e6a5d2fa5
- https://github.com/torvalds/linux/commit/7b789836f434c87168eab067cfbed1ec4783dffd
- https://github.com/torvalds/linux/commit/7b789836f434c87168eab067cfbed1ec4783dffd
- https://github.com/torvalds/linux/commit/f778a636713a435d3a922c60b1622a91136560c1
- https://github.com/torvalds/linux/commit/f778a636713a435d3a922c60b1622a91136560c1
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.6.bz2
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.6.bz2
Modified: 2024-11-21
CVE-2012-6542
The llc_ui_getname function in net/llc/af_llc.c in the Linux kernel before 3.6 has an incorrect return value in certain circumstances, which allows local users to obtain sensitive information from kernel stack memory via a crafted application that leverages an uninitialized pointer argument.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3592aaeb80290bda0f2cf0b5456c97bfc638b192
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3592aaeb80290bda0f2cf0b5456c97bfc638b192
- RHSA-2013:1645
- RHSA-2013:1645
- [oss-security] 20130305 CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- [oss-security] 20130305 CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- USN-1805-1
- USN-1805-1
- USN-1808-1
- USN-1808-1
- https://github.com/torvalds/linux/commit/3592aaeb80290bda0f2cf0b5456c97bfc638b192
- https://github.com/torvalds/linux/commit/3592aaeb80290bda0f2cf0b5456c97bfc638b192
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.6.bz2
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.6.bz2
Modified: 2024-11-21
CVE-2012-6545
The Bluetooth RFCOMM implementation in the Linux kernel before 3.6 does not properly initialize certain structures, which allows local users to obtain sensitive information from kernel memory via a crafted application.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9344a972961d1a6d2c04d9008b13617bcb6ec2ef
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9344a972961d1a6d2c04d9008b13617bcb6ec2ef
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9ad2de43f1aee7e7274a4e0d41465489299e344b
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9ad2de43f1aee7e7274a4e0d41465489299e344b
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f9432c5ec8b1e9a09b9b0e5569e3c73db8de432a
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=f9432c5ec8b1e9a09b9b0e5569e3c73db8de432a
- RHSA-2013:1645
- RHSA-2013:1645
- [oss-security] 20130305 CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- [oss-security] 20130305 CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- USN-1805-1
- USN-1805-1
- USN-1808-1
- USN-1808-1
- https://github.com/torvalds/linux/commit/9344a972961d1a6d2c04d9008b13617bcb6ec2ef
- https://github.com/torvalds/linux/commit/9344a972961d1a6d2c04d9008b13617bcb6ec2ef
- https://github.com/torvalds/linux/commit/9ad2de43f1aee7e7274a4e0d41465489299e344b
- https://github.com/torvalds/linux/commit/9ad2de43f1aee7e7274a4e0d41465489299e344b
- https://github.com/torvalds/linux/commit/f9432c5ec8b1e9a09b9b0e5569e3c73db8de432a
- https://github.com/torvalds/linux/commit/f9432c5ec8b1e9a09b9b0e5569e3c73db8de432a
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.6.bz2
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.6.bz2
Modified: 2024-11-21
CVE-2012-6546
The ATM implementation in the Linux kernel before 3.6 does not initialize certain structures, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3c0c5cfdcd4d69ffc4b9c0907cec99039f30a50a
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=3c0c5cfdcd4d69ffc4b9c0907cec99039f30a50a
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e862f1a9b7df4e8196ebec45ac62295138aa3fc2
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e862f1a9b7df4e8196ebec45ac62295138aa3fc2
- RHSA-2013:0744
- RHSA-2013:0744
- [oss-security] 20130305 CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- [oss-security] 20130305 CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- USN-1805-1
- USN-1805-1
- USN-1808-1
- USN-1808-1
- https://github.com/torvalds/linux/commit/3c0c5cfdcd4d69ffc4b9c0907cec99039f30a50a
- https://github.com/torvalds/linux/commit/3c0c5cfdcd4d69ffc4b9c0907cec99039f30a50a
- https://github.com/torvalds/linux/commit/e862f1a9b7df4e8196ebec45ac62295138aa3fc2
- https://github.com/torvalds/linux/commit/e862f1a9b7df4e8196ebec45ac62295138aa3fc2
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.6.bz2
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.6.bz2
Modified: 2024-11-21
CVE-2012-6547
The __tun_chr_ioctl function in drivers/net/tun.c in the Linux kernel before 3.6 does not initialize a certain structure, which allows local users to obtain sensitive information from kernel stack memory via a crafted application.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a117dacde0288f3ec60b6e5bcedae8fa37ee0dfc
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a117dacde0288f3ec60b6e5bcedae8fa37ee0dfc
- RHSA-2013:0744
- RHSA-2013:0744
- MDVSA-2013:176
- MDVSA-2013:176
- [oss-security] 20130305 CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- [oss-security] 20130305 CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- https://github.com/torvalds/linux/commit/a117dacde0288f3ec60b6e5bcedae8fa37ee0dfc
- https://github.com/torvalds/linux/commit/a117dacde0288f3ec60b6e5bcedae8fa37ee0dfc
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.6.bz2
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.6.bz2
Modified: 2024-11-21
CVE-2013-0228
The xen_iret function in arch/x86/xen/xen-asm_32.S in the Linux kernel before 3.7.9 on 32-bit Xen paravirt_ops platforms does not properly handle an invalid value in the DS segment register, which allows guest OS users to gain guest OS privileges via a crafted application.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=13d2b4d11d69a92574a55bfd985cfb0ca77aebdc
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=13d2b4d11d69a92574a55bfd985cfb0ca77aebdc
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.9
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.9
- MDVSA-2013:176
- MDVSA-2013:176
- [oss-security] 20130213 Xen Security Advisory 42 (CVE-2013-0228) - Linux kernel hits general protection if %ds is corrupt for 32-bit PVOPS.
- [oss-security] 20130213 Xen Security Advisory 42 (CVE-2013-0228) - Linux kernel hits general protection if %ds is corrupt for 32-bit PVOPS.
- USN-1795-1
- USN-1795-1
- USN-1796-1
- USN-1796-1
- USN-1797-1
- USN-1797-1
- USN-1805-1
- USN-1805-1
- USN-1808-1
- USN-1808-1
- https://bugzilla.redhat.com/show_bug.cgi?id=906309
- https://bugzilla.redhat.com/show_bug.cgi?id=906309
- https://github.com/torvalds/linux/commit/13d2b4d11d69a92574a55bfd985cfb0ca77aebdc
- https://github.com/torvalds/linux/commit/13d2b4d11d69a92574a55bfd985cfb0ca77aebdc
Modified: 2024-11-21
CVE-2013-0268
The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before 3.7.6 allows local users to bypass intended capability restrictions by executing a crafted application as root, as demonstrated by msr32.c.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c903f0456bc69176912dee6dd25c6a66ee1aed00
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c903f0456bc69176912dee6dd25c6a66ee1aed00
- SUSE-SU-2013:0674
- SUSE-SU-2013:0674
- openSUSE-SU-2013:1187
- openSUSE-SU-2013:1187
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.6
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.6
- [oss-security] 20130207 Re: CVE request -- Linux kernel: x86/msr: /dev/cpu/*/msr local privilege escalation
- [oss-security] 20130207 Re: CVE request -- Linux kernel: x86/msr: /dev/cpu/*/msr local privilege escalation
- https://bugzilla.redhat.com/show_bug.cgi?id=908693
- https://bugzilla.redhat.com/show_bug.cgi?id=908693
- https://github.com/torvalds/linux/commit/c903f0456bc69176912dee6dd25c6a66ee1aed00
- https://github.com/torvalds/linux/commit/c903f0456bc69176912dee6dd25c6a66ee1aed00
Modified: 2024-11-21
CVE-2013-0343
The ipv6_create_tempaddr function in net/ipv6/addrconf.c in the Linux kernel through 3.8 does not properly handle problems with the generation of IPv6 temporary addresses, which allows remote attackers to cause a denial of service (excessive retries and address-generation outage), and consequently obtain sensitive information, via ICMPv6 Router Advertisement (RA) messages.
- openSUSE-SU-2014:0204
- openSUSE-SU-2014:0204
- [oss-security] 20121205 Re: Linux kernel handling of IPv6 temporary addresses
- [oss-security] 20121205 Re: Linux kernel handling of IPv6 temporary addresses
- [oss-security] 20130116 Re: Linux kernel handling of IPv6 temporary addresses
- [oss-security] 20130116 Re: Linux kernel handling of IPv6 temporary addresses
- [oss-security] 20130121 Re: Linux kernel handling of IPv6 temporary addresses
- [oss-security] 20130121 Re: Linux kernel handling of IPv6 temporary addresses
- RHSA-2013:1449
- RHSA-2013:1449
- RHSA-2013:1490
- RHSA-2013:1490
- RHSA-2013:1645
- RHSA-2013:1645
- [oss-security] 20130222 Re: Linux kernel handling of IPv6 temporary addresses
- [oss-security] 20130222 Re: Linux kernel handling of IPv6 temporary addresses
- USN-1976-1
- USN-1976-1
- USN-1977-1
- USN-1977-1
- USN-2019-1
- USN-2019-1
- USN-2020-1
- USN-2020-1
- USN-2021-1
- USN-2021-1
- USN-2022-1
- USN-2022-1
- USN-2023-1
- USN-2023-1
- USN-2024-1
- USN-2024-1
- USN-2038-1
- USN-2038-1
- USN-2039-1
- USN-2039-1
- USN-2050-1
- USN-2050-1
- https://bugzilla.redhat.com/show_bug.cgi?id=914664
- https://bugzilla.redhat.com/show_bug.cgi?id=914664
Modified: 2024-11-21
CVE-2013-0349
The hidp_setup_hid function in net/bluetooth/hidp/core.c in the Linux kernel before 3.7.6 does not properly copy a certain name field, which allows local users to obtain sensitive information from kernel memory by setting a long name and making an HIDPCONNADD ioctl call.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0a9ab9bdb3e891762553f667066190c1d22ad62b
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0a9ab9bdb3e891762553f667066190c1d22ad62b
- RHSA-2013:0744
- RHSA-2013:0744
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.6
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.6
- [oss-security] 20130222 Re: CVE request: Linux kernel: Bluetooth HIDP information disclosure
- [oss-security] 20130222 Re: CVE request: Linux kernel: Bluetooth HIDP information disclosure
- USN-1805-1
- USN-1805-1
- USN-1808-1
- USN-1808-1
- https://bugzilla.redhat.com/show_bug.cgi?id=914298
- https://bugzilla.redhat.com/show_bug.cgi?id=914298
- https://github.com/torvalds/linux/commit/0a9ab9bdb3e891762553f667066190c1d22ad62b
- https://github.com/torvalds/linux/commit/0a9ab9bdb3e891762553f667066190c1d22ad62b
Modified: 2024-11-21
CVE-2013-0871
Race condition in the ptrace functionality in the Linux kernel before 3.7.5 allows local users to gain privileges via a PTRACE_SETREGS ptrace system call in a crafted application, as demonstrated by ptrace_death.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9899d11f654474d2d54ea52ceaa2a1f4db3abd68
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=9899d11f654474d2d54ea52ceaa2a1f4db3abd68
- SUSE-SU-2013:0341
- SUSE-SU-2013:0341
- SUSE-SU-2013:0674
- SUSE-SU-2013:0674
- openSUSE-SU-2013:0925
- openSUSE-SU-2013:0925
- RHSA-2013:0567
- RHSA-2013:0567
- RHSA-2013:0661
- RHSA-2013:0661
- RHSA-2013:0662
- RHSA-2013:0662
- RHSA-2013:0695
- RHSA-2013:0695
- DSA-2632
- DSA-2632
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.5
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.5
- [oss-security] 20130215 Linux kernel race condition with PTRACE_SETREGS (CVE-2013-0871)
- [oss-security] 20130215 Linux kernel race condition with PTRACE_SETREGS (CVE-2013-0871)
- USN-1736-1
- USN-1736-1
- USN-1737-1
- USN-1737-1
- USN-1738-1
- USN-1738-1
- USN-1739-1
- USN-1739-1
- USN-1740-1
- USN-1740-1
- USN-1741-1
- USN-1741-1
- USN-1742-1
- USN-1742-1
- USN-1743-1
- USN-1743-1
- USN-1744-1
- USN-1744-1
- USN-1745-1
- USN-1745-1
- https://bugzilla.redhat.com/show_bug.cgi?id=911937
- https://bugzilla.redhat.com/show_bug.cgi?id=911937
- https://github.com/torvalds/linux/commit/9899d11f654474d2d54ea52ceaa2a1f4db3abd68
- https://github.com/torvalds/linux/commit/9899d11f654474d2d54ea52ceaa2a1f4db3abd68
Modified: 2024-11-21
CVE-2013-0913
Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted application that triggers many relocation copies, and potentially leads to a race condition.
- http://git.chromium.org/gitweb/?p=chromiumos/third_party/kernel.git%3Ba=commit%3Bh=c79efdf2b7f68f985922a8272d64269ecd490477
- http://git.chromium.org/gitweb/?p=chromiumos/third_party/kernel.git%3Ba=commit%3Bh=c79efdf2b7f68f985922a8272d64269ecd490477
- http://googlechromereleases.blogspot.com/2013/03/stable-channel-update-for-chrome-os_15.html
- http://googlechromereleases.blogspot.com/2013/03/stable-channel-update-for-chrome-os_15.html
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0925
- openSUSE-SU-2013:0925
- [oss-security] 20130311 CVE-2013-0913 Linux kernel i915 integer overflow
- [oss-security] 20130311 CVE-2013-0913 Linux kernel i915 integer overflow
- [oss-security] 20130313 Re: CVE-2013-0913 Linux kernel i915 integer overflow
- [oss-security] 20130313 Re: CVE-2013-0913 Linux kernel i915 integer overflow
- [oss-security] 20130314 Re: CVE-2013-0913 Linux kernel i915 integer overflow
- [oss-security] 20130314 Re: CVE-2013-0913 Linux kernel i915 integer overflow
- RHSA-2013:0744
- RHSA-2013:0744
- USN-1809-1
- USN-1809-1
- USN-1811-1
- USN-1811-1
- USN-1812-1
- USN-1812-1
- USN-1813-1
- USN-1813-1
- USN-1814-1
- USN-1814-1
- https://bugzilla.redhat.com/show_bug.cgi?id=920471
- https://bugzilla.redhat.com/show_bug.cgi?id=920471
- https://code.google.com/p/chromium-os/issues/detail?id=39733
- https://code.google.com/p/chromium-os/issues/detail?id=39733
- https://gerrit.chromium.org/gerrit/45118
- https://gerrit.chromium.org/gerrit/45118
- [linux-kernel] 20130311 [PATCH] drm/i915: bounds check execbuffer relocations
- [linux-kernel] 20130311 [PATCH] drm/i915: bounds check execbuffer relocations
Modified: 2024-11-21
CVE-2013-1767
Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5f00110f7273f9ff04ac69a5f85bb535a4fd0987
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5f00110f7273f9ff04ac69a5f85bb535a4fd0987
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0925
- openSUSE-SU-2013:0925
- RHSA-2013:0744
- RHSA-2013:0744
- RHSA-2013:0882
- RHSA-2013:0882
- RHSA-2013:0928
- RHSA-2013:0928
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.10
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.10
- MDVSA-2013:176
- MDVSA-2013:176
- [oss-security] 20130225 Re: kernel: tmpfs use-after-free
- [oss-security] 20130225 Re: kernel: tmpfs use-after-free
- USN-1787-1
- USN-1787-1
- USN-1788-1
- USN-1788-1
- USN-1792-1
- USN-1792-1
- USN-1793-1
- USN-1793-1
- USN-1794-1
- USN-1794-1
- USN-1795-1
- USN-1795-1
- USN-1796-1
- USN-1796-1
- USN-1797-1
- USN-1797-1
- USN-1798-1
- USN-1798-1
- https://bugzilla.redhat.com/show_bug.cgi?id=915592
- https://bugzilla.redhat.com/show_bug.cgi?id=915592
- https://github.com/torvalds/linux/commit/5f00110f7273f9ff04ac69a5f85bb535a4fd0987
- https://github.com/torvalds/linux/commit/5f00110f7273f9ff04ac69a5f85bb535a4fd0987
Modified: 2024-11-21
CVE-2013-1773
Buffer overflow in the VFAT filesystem implementation in the Linux kernel before 3.3 allows local users to gain privileges or cause a denial of service (system crash) via a VFAT write operation on a filesystem with the utf8 mount option, which is not properly handled during UTF-8 to UTF-16 conversion.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0720a06a7518c9d0c0125bd5d1f3b6264c55c3dd
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0720a06a7518c9d0c0125bd5d1f3b6264c55c3dd
- RHSA-2013:0744
- RHSA-2013:0744
- RHSA-2013:0928
- RHSA-2013:0928
- RHSA-2013:1026
- RHSA-2013:1026
- 23248
- 23248
- http://www.kernel.org/pub/linux/kernel/v3.x/patch-3.3.bz2
- http://www.kernel.org/pub/linux/kernel/v3.x/patch-3.3.bz2
- [oss-security] 20130226 Re: CVE request - Linux kernel: VFAT slab-based buffer overflow
- [oss-security] 20130226 Re: CVE request - Linux kernel: VFAT slab-based buffer overflow
- 88310
- 88310
- 58200
- 58200
- https://bugzilla.redhat.com/show_bug.cgi?id=916115
- https://bugzilla.redhat.com/show_bug.cgi?id=916115
- https://github.com/torvalds/linux/commit/0720a06a7518c9d0c0125bd5d1f3b6264c55c3dd
- https://github.com/torvalds/linux/commit/0720a06a7518c9d0c0125bd5d1f3b6264c55c3dd
Modified: 2024-11-21
CVE-2013-1774
The chase_port function in drivers/usb/serial/io_ti.c in the Linux kernel before 3.7.4 allows local users to cause a denial of service (NULL pointer dereference and system crash) via an attempted /dev/ttyUSB read or write operation on a disconnected Edgeport USB serial converter.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1ee0a224bc9aad1de496c795f96bc6ba2c394811
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1ee0a224bc9aad1de496c795f96bc6ba2c394811
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0925
- openSUSE-SU-2013:0925
- SUSE-SU-2013:1182
- SUSE-SU-2013:1182
- SUSE-SU-2013:1474
- SUSE-SU-2013:1474
- RHSA-2013:0744
- RHSA-2013:0744
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.4
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.4
- [oss-security] 20130227 Re: CVE request: Linux kernel: USB: io_ti: NULL pointer dereference
- [oss-security] 20130227 Re: CVE request: Linux kernel: USB: io_ti: NULL pointer dereference
- USN-1805-1
- USN-1805-1
- USN-1808-1
- USN-1808-1
- http://xorl.wordpress.com/2013/05/18/cve-2013-1774-linux-kernel-edgeport-usb-serial-converter-null-pointer-dereference/
- http://xorl.wordpress.com/2013/05/18/cve-2013-1774-linux-kernel-edgeport-usb-serial-converter-null-pointer-dereference/
- https://bugzilla.redhat.com/show_bug.cgi?id=916191
- https://bugzilla.redhat.com/show_bug.cgi?id=916191
- https://github.com/torvalds/linux/commit/1ee0a224bc9aad1de496c795f96bc6ba2c394811
- https://github.com/torvalds/linux/commit/1ee0a224bc9aad1de496c795f96bc6ba2c394811
Modified: 2024-11-21
CVE-2013-1792
Race condition in the install_user_keyrings function in security/keys/process_keys.c in the Linux kernel before 3.8.3 allows local users to cause a denial of service (NULL pointer dereference and system crash) via crafted keyctl system calls that trigger keyring operations in simultaneous threads.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0da9dfdd2cd9889201bc6f6f43580c99165cd087
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0da9dfdd2cd9889201bc6f6f43580c99165cd087
- openSUSE-SU-2013:1187
- openSUSE-SU-2013:1187
- openSUSE-SU-2014:0204
- openSUSE-SU-2014:0204
- RHSA-2013:0744
- RHSA-2013:0744
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.3
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.3
- MDVSA-2013:176
- MDVSA-2013:176
- [oss-security] 20130307 CVE-2013-1792 Linux kernel: KEYS: race with concurrent install_user_keyrings()
- [oss-security] 20130307 CVE-2013-1792 Linux kernel: KEYS: race with concurrent install_user_keyrings()
- USN-1787-1
- USN-1787-1
- USN-1788-1
- USN-1788-1
- USN-1792-1
- USN-1792-1
- USN-1793-1
- USN-1793-1
- USN-1794-1
- USN-1794-1
- USN-1795-1
- USN-1795-1
- USN-1796-1
- USN-1796-1
- USN-1797-1
- USN-1797-1
- USN-1798-1
- USN-1798-1
- https://bugzilla.redhat.com/show_bug.cgi?id=916646
- https://bugzilla.redhat.com/show_bug.cgi?id=916646
- https://github.com/torvalds/linux/commit/0da9dfdd2cd9889201bc6f6f43580c99165cd087
- https://github.com/torvalds/linux/commit/0da9dfdd2cd9889201bc6f6f43580c99165cd087
Modified: 2024-11-21
CVE-2013-1796
The kvm_set_msr_common function in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 does not ensure a required time_page alignment during an MSR_KVM_SYSTEM_TIME operation, which allows guest OS users to cause a denial of service (buffer overflow and host OS memory corruption) or possibly have unspecified other impact via a crafted application.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c300aa64ddf57d9c5d9c898a64b36877345dd4a9
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c300aa64ddf57d9c5d9c898a64b36877345dd4a9
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0925
- openSUSE-SU-2013:0925
- openSUSE-SU-2013:1187
- openSUSE-SU-2013:1187
- RHSA-2013:0727
- RHSA-2013:0727
- RHSA-2013:0744
- RHSA-2013:0744
- RHSA-2013:0746
- RHSA-2013:0746
- RHSA-2013:0928
- RHSA-2013:0928
- RHSA-2013:1026
- RHSA-2013:1026
- MDVSA-2013:176
- MDVSA-2013:176
- [oss-security] 20130320 linux kernel: kvm: CVE-2013-179[6..8]
- [oss-security] 20130320 linux kernel: kvm: CVE-2013-179[6..8]
- 58607
- 58607
- USN-1805-1
- USN-1805-1
- USN-1808-1
- USN-1808-1
- USN-1809-1
- USN-1809-1
- USN-1812-1
- USN-1812-1
- USN-1813-1
- USN-1813-1
- https://bugzilla.redhat.com/show_bug.cgi?id=917012
- https://bugzilla.redhat.com/show_bug.cgi?id=917012
- https://github.com/torvalds/linux/commit/c300aa64ddf57d9c5d9c898a64b36877345dd4a9
- https://github.com/torvalds/linux/commit/c300aa64ddf57d9c5d9c898a64b36877345dd4a9
Modified: 2024-11-21
CVE-2013-1797
Use-after-free vulnerability in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 allows guest OS users to cause a denial of service (host OS memory corruption) or possibly have unspecified other impact via a crafted application that triggers use of a guest physical address (GPA) in (1) movable or (2) removable memory during an MSR_KVM_SYSTEM_TIME kvm_set_msr_common operation.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0b79459b482e85cb7426aa7da683a9f2c97aeae1
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=0b79459b482e85cb7426aa7da683a9f2c97aeae1
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0925
- openSUSE-SU-2013:0925
- openSUSE-SU-2013:1187
- openSUSE-SU-2013:1187
- RHSA-2013:0727
- RHSA-2013:0727
- RHSA-2013:0744
- RHSA-2013:0744
- RHSA-2013:0746
- RHSA-2013:0746
- RHSA-2013:0928
- RHSA-2013:0928
- RHSA-2013:1026
- RHSA-2013:1026
- MDVSA-2013:176
- MDVSA-2013:176
- [oss-security] 20130320 linux kernel: kvm: CVE-2013-179[6..8]
- [oss-security] 20130320 linux kernel: kvm: CVE-2013-179[6..8]
- USN-1809-1
- USN-1809-1
- USN-1812-1
- USN-1812-1
- USN-1813-1
- USN-1813-1
- https://bugzilla.redhat.com/show_bug.cgi?id=917013
- https://bugzilla.redhat.com/show_bug.cgi?id=917013
- https://github.com/torvalds/linux/commit/0b79459b482e85cb7426aa7da683a9f2c97aeae1
- https://github.com/torvalds/linux/commit/0b79459b482e85cb7426aa7da683a9f2c97aeae1
Modified: 2024-11-21
CVE-2013-1798
The ioapic_read_indirect function in virt/kvm/ioapic.c in the Linux kernel through 3.8.4 does not properly handle a certain combination of invalid IOAPIC_REG_SELECT and IOAPIC_REG_WINDOW operations, which allows guest OS users to obtain sensitive information from host OS memory or cause a denial of service (host OS OOPS) via a crafted application.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a2c118bfab8bc6b8bb213abfc35201e441693d55
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a2c118bfab8bc6b8bb213abfc35201e441693d55
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0925
- openSUSE-SU-2013:0925
- openSUSE-SU-2013:1187
- openSUSE-SU-2013:1187
- http://packetstormsecurity.com/files/157233/Kernel-Live-Patch-Security-Notice-LSN-0065-1.html
- http://packetstormsecurity.com/files/157233/Kernel-Live-Patch-Security-Notice-LSN-0065-1.html
- RHSA-2013:0727
- RHSA-2013:0727
- RHSA-2013:0744
- RHSA-2013:0744
- RHSA-2013:0746
- RHSA-2013:0746
- RHSA-2013:0928
- RHSA-2013:0928
- RHSA-2013:1026
- RHSA-2013:1026
- MDVSA-2013:176
- MDVSA-2013:176
- [oss-security] 20130320 linux kernel: kvm: CVE-2013-179[6..8]
- [oss-security] 20130320 linux kernel: kvm: CVE-2013-179[6..8]
- USN-1809-1
- USN-1809-1
- USN-1812-1
- USN-1812-1
- USN-1813-1
- USN-1813-1
- https://bugzilla.redhat.com/show_bug.cgi?id=917017
- https://bugzilla.redhat.com/show_bug.cgi?id=917017
- https://github.com/torvalds/linux/commit/a2c118bfab8bc6b8bb213abfc35201e441693d55
- https://github.com/torvalds/linux/commit/a2c118bfab8bc6b8bb213abfc35201e441693d55
Modified: 2024-11-21
CVE-2013-1826
The xfrm_state_netlink function in net/xfrm/xfrm_user.c in the Linux kernel before 3.5.7 does not properly handle error conditions in dump_one_state function calls, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=864745d291b5ba80ea0bd0edcbe67273de368836
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=864745d291b5ba80ea0bd0edcbe67273de368836
- RHSA-2013:0744
- RHSA-2013:0744
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.7
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.7
- [oss-security] 20130307 Re: CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- [oss-security] 20130307 Re: CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- USN-1829-1
- USN-1829-1
- https://bugzilla.redhat.com/show_bug.cgi?id=919384
- https://bugzilla.redhat.com/show_bug.cgi?id=919384
- https://github.com/torvalds/linux/commit/864745d291b5ba80ea0bd0edcbe67273de368836
- https://github.com/torvalds/linux/commit/864745d291b5ba80ea0bd0edcbe67273de368836
Modified: 2024-11-21
CVE-2013-1827
net/dccp/ccid.h in the Linux kernel before 3.5.4 allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability for a certain (1) sender or (2) receiver getsockopt call.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=276bdb82dedb290511467a5a4fdbe9f0b52dce6f
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=276bdb82dedb290511467a5a4fdbe9f0b52dce6f
- RHSA-2013:0744
- RHSA-2013:0744
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.4
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.5.4
- [oss-security] 20130307 Re: CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- [oss-security] 20130307 Re: CVE Requests (maybe): Linux kernel: various info leaks, some NULL ptr derefs
- https://bugzilla.redhat.com/show_bug.cgi?id=919164
- https://bugzilla.redhat.com/show_bug.cgi?id=919164
- https://github.com/torvalds/linux/commit/276bdb82dedb290511467a5a4fdbe9f0b52dce6f
- https://github.com/torvalds/linux/commit/276bdb82dedb290511467a5a4fdbe9f0b52dce6f
Modified: 2024-11-21
CVE-2013-1928
The do_video_set_spu_palette function in fs/compat_ioctl.c in the Linux kernel before 3.6.5 on unspecified architectures lacks a certain error check, which might allow local users to obtain sensitive information from kernel stack memory via a crafted VIDEO_SET_SPU_PALETTE ioctl call on a /dev/dvb device.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=12176503366885edd542389eed3aaf94be163fdb
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=12176503366885edd542389eed3aaf94be163fdb
- openSUSE-SU-2013:0847
- openSUSE-SU-2013:0847
- SUSE-SU-2013:0856
- SUSE-SU-2013:0856
- RHSA-2013:1645
- RHSA-2013:1645
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.6.5
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.6.5
- [oss-security] 20130405 Re: CVE Request: kernel information leak in fs/compat_ioctl.c VIDEO_SET_SPU_PALETTE
- [oss-security] 20130405 Re: CVE Request: kernel information leak in fs/compat_ioctl.c VIDEO_SET_SPU_PALETTE
- [oss-security] 20130409 Re: CVE Request: kernel information leak in fs/compat_ioctl.c VIDEO_SET_SPU_PALETTE
- [oss-security] 20130409 Re: CVE Request: kernel information leak in fs/compat_ioctl.c VIDEO_SET_SPU_PALETTE
- USN-1829-1
- USN-1829-1
- https://bugzilla.redhat.com/show_bug.cgi?id=949567
- https://bugzilla.redhat.com/show_bug.cgi?id=949567
- https://github.com/torvalds/linux/commit/12176503366885edd542389eed3aaf94be163fdb
- https://github.com/torvalds/linux/commit/12176503366885edd542389eed3aaf94be163fdb
Modified: 2024-11-21
CVE-2013-2141
The do_tkill function in kernel/signal.c in the Linux kernel before 3.8.9 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory via a crafted application that makes a (1) tkill or (2) tgkill system call.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b9e146d8eb3b9ecae5086d373b50fa0c1f3e7f0f
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b9e146d8eb3b9ecae5086d373b50fa0c1f3e7f0f
- openSUSE-SU-2013:1971
- openSUSE-SU-2013:1971
- RHSA-2013:1801
- RHSA-2013:1801
- 55055
- 55055
- DSA-2766
- DSA-2766
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.9
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.9
- MDVSA-2013:176
- MDVSA-2013:176
- [oss-security] 20130604 Re: CVE Request: kernel info leak in tkill/tgkill
- [oss-security] 20130604 Re: CVE Request: kernel info leak in tkill/tgkill
- USN-1899-1
- USN-1899-1
- USN-1900-1
- USN-1900-1
- https://bugzilla.redhat.com/show_bug.cgi?id=970873
- https://bugzilla.redhat.com/show_bug.cgi?id=970873
- https://github.com/torvalds/linux/commit/b9e146d8eb3b9ecae5086d373b50fa0c1f3e7f0f
- https://github.com/torvalds/linux/commit/b9e146d8eb3b9ecae5086d373b50fa0c1f3e7f0f
Modified: 2024-11-21
CVE-2013-2164
The mmc_ioctl_cdrom_read_data function in drivers/cdrom/cdrom.c in the Linux kernel through 3.10 allows local users to obtain sensitive information from kernel memory via a read operation on a malfunctioning CD-ROM drive.
- http://git.kernel.org/cgit/linux/kernel/git/next/linux-next.git/commit/drivers/cdrom/cdrom.c?id=050e4b8fb7cdd7096c987a9cd556029c622c7fe2
- http://git.kernel.org/cgit/linux/kernel/git/next/linux-next.git/commit/drivers/cdrom/cdrom.c?id=050e4b8fb7cdd7096c987a9cd556029c622c7fe2
- SUSE-SU-2013:1473
- SUSE-SU-2013:1473
- SUSE-SU-2013:1474
- SUSE-SU-2013:1474
- openSUSE-SU-2013:1971
- openSUSE-SU-2013:1971
- RHSA-2013:1166
- RHSA-2013:1166
- RHSA-2013:1645
- RHSA-2013:1645
- DSA-2766
- DSA-2766
- [oss-security] 20130610 Re: CVE Request: Linux Kernel - Leak information in cdrom driver.
- [oss-security] 20130610 Re: CVE Request: Linux Kernel - Leak information in cdrom driver.
- USN-1912-1
- USN-1912-1
- USN-1913-1
- USN-1913-1
- USN-1941-1
- USN-1941-1
- USN-1942-1
- USN-1942-1
- https://bugzilla.redhat.com/show_bug.cgi?id=973100
- https://bugzilla.redhat.com/show_bug.cgi?id=973100
Modified: 2024-11-21
CVE-2013-2234
The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify interface of an IPSec key_socket.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a5cc68f3d63306d0d288f31edfc2ae6ef8ecd887
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a5cc68f3d63306d0d288f31edfc2ae6ef8ecd887
- SUSE-SU-2013:1473
- SUSE-SU-2013:1473
- SUSE-SU-2013:1474
- SUSE-SU-2013:1474
- openSUSE-SU-2013:1971
- openSUSE-SU-2013:1971
- RHSA-2013:1166
- RHSA-2013:1166
- RHSA-2013:1645
- RHSA-2013:1645
- DSA-2766
- DSA-2766
- [oss-security] 20130702 Re: CVE Request: information leak in AF_KEY notify messages
- [oss-security] 20130702 Re: CVE Request: information leak in AF_KEY notify messages
- USN-1912-1
- USN-1912-1
- USN-1913-1
- USN-1913-1
- USN-1938-1
- USN-1938-1
- USN-1941-1
- USN-1941-1
- USN-1942-1
- USN-1942-1
- USN-1943-1
- USN-1943-1
- USN-1944-1
- USN-1944-1
- USN-1945-1
- USN-1945-1
- USN-1946-1
- USN-1946-1
- USN-1947-1
- USN-1947-1
- https://bugzilla.redhat.com/show_bug.cgi?id=980995
- https://bugzilla.redhat.com/show_bug.cgi?id=980995
- https://github.com/torvalds/linux/commit/a5cc68f3d63306d0d288f31edfc2ae6ef8ecd887
- https://github.com/torvalds/linux/commit/a5cc68f3d63306d0d288f31edfc2ae6ef8ecd887
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.10.bz2
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.10.bz2
Modified: 2024-11-21
CVE-2013-2851
Format string vulnerability in the register_disk function in block/genhd.c in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and writing format string specifiers to /sys/module/md_mod/parameters/new_array in order to create a crafted /dev/md device name.
- SUSE-SU-2013:1473
- SUSE-SU-2013:1473
- SUSE-SU-2013:1474
- SUSE-SU-2013:1474
- openSUSE-SU-2013:1971
- openSUSE-SU-2013:1971
- [linux-kernel] 20130606 [PATCH 1/8] block: do not pass disk names as format strings
- [linux-kernel] 20130606 [PATCH 1/8] block: do not pass disk names as format strings
- RHSA-2013:1645
- RHSA-2013:1645
- RHSA-2013:1783
- RHSA-2013:1783
- RHSA-2014:0284
- RHSA-2014:0284
- DSA-2766
- DSA-2766
- [oss-security] 20130606 Linux kernel format string flaws
- [oss-security] 20130606 Linux kernel format string flaws
- USN-1912-1
- USN-1912-1
- USN-1913-1
- USN-1913-1
- USN-1941-1
- USN-1941-1
- USN-1942-1
- USN-1942-1
- https://bugzilla.redhat.com/show_bug.cgi?id=969515
- https://bugzilla.redhat.com/show_bug.cgi?id=969515
Modified: 2024-11-21
CVE-2013-2888
Multiple array index errors in drivers/hid/hid-core.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11 allow physically proximate attackers to execute arbitrary code or cause a denial of service (heap memory corruption) via a crafted device that provides an invalid Report ID.
- [linux-input] 20130828 [PATCH 01/14] HID: validate HID report id size
- [linux-input] 20130828 [PATCH 01/14] HID: validate HID report id size
- [oss-security] 20130828 Linux HID security flaws
- [oss-security] 20130828 Linux HID security flaws
- RHSA-2013:1490
- RHSA-2013:1490
- RHSA-2013:1645
- RHSA-2013:1645
- DSA-2766
- DSA-2766
- USN-1976-1
- USN-1976-1
- USN-1977-1
- USN-1977-1
- USN-1995-1
- USN-1995-1
- USN-1998-1
- USN-1998-1
- USN-2019-1
- USN-2019-1
- USN-2021-1
- USN-2021-1
- USN-2022-1
- USN-2022-1
- USN-2024-1
- USN-2024-1
- USN-2038-1
- USN-2038-1
- USN-2039-1
- USN-2039-1
- USN-2050-1
- USN-2050-1
Modified: 2024-11-21
CVE-2013-2889
drivers/hid/hid-zpff.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_ZEROPLUS is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.
- [linux-input] 20130828 [PATCH 03/14] HID: zeroplus: validate output report details
- [linux-input] 20130828 [PATCH 03/14] HID: zeroplus: validate output report details
- [oss-security] 20130828 Linux HID security flaws
- [oss-security] 20130828 Linux HID security flaws
- RHSA-2013:1645
- RHSA-2013:1645
- 62042
- 62042
- USN-2015-1
- USN-2015-1
- USN-2016-1
- USN-2016-1
- USN-2019-1
- USN-2019-1
- USN-2020-1
- USN-2020-1
- USN-2021-1
- USN-2021-1
- USN-2022-1
- USN-2022-1
- USN-2023-1
- USN-2023-1
- USN-2024-1
- USN-2024-1
- USN-2038-1
- USN-2038-1
- USN-2039-1
- USN-2039-1
- USN-2050-1
- USN-2050-1
Modified: 2024-11-21
CVE-2013-2892
drivers/hid/hid-pl.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_PANTHERLORD is enabled, allows physically proximate attackers to cause a denial of service (heap-based out-of-bounds write) via a crafted device.
- [linux-input] 20130828 [PATCH 06/14] HID: pantherlord: validate output report details
- [linux-input] 20130828 [PATCH 06/14] HID: pantherlord: validate output report details
- [oss-security] 20130828 Linux HID security flaws
- [oss-security] 20130828 Linux HID security flaws
- RHSA-2013:1490
- RHSA-2013:1490
- RHSA-2013:1645
- RHSA-2013:1645
- DSA-2766
- DSA-2766
- 62049
- 62049
- USN-1976-1
- USN-1976-1
- USN-1977-1
- USN-1977-1
- USN-1995-1
- USN-1995-1
- USN-1998-1
- USN-1998-1
- USN-2019-1
- USN-2019-1
- USN-2021-1
- USN-2021-1
- USN-2022-1
- USN-2022-1
- USN-2024-1
- USN-2024-1
- USN-2038-1
- USN-2038-1
- USN-2039-1
- USN-2039-1
- USN-2050-1
- USN-2050-1
Modified: 2024-11-21
CVE-2013-2929
The Linux kernel before 3.12.2 does not properly use the get_dumpable function, which allows local users to bypass intended ptrace restrictions or obtain sensitive information from IA64 scratch registers via a crafted application, related to kernel/ptrace.c and arch/ia64/include/asm/processor.h.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d049f74f2dbe71354d43d393ac3a188947811348
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d049f74f2dbe71354d43d393ac3a188947811348
- SUSE-SU-2015:0481
- SUSE-SU-2015:0481
- openSUSE-SU-2015:0566
- openSUSE-SU-2015:0566
- RHSA-2014:0100
- RHSA-2014:0100
- RHSA-2014:0159
- RHSA-2014:0159
- RHSA-2014:0285
- RHSA-2014:0285
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.12.2
- http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.12.2
- 64111
- 64111
- USN-2070-1
- USN-2070-1
- USN-2075-1
- USN-2075-1
- USN-2109-1
- USN-2109-1
- USN-2110-1
- USN-2110-1
- USN-2111-1
- USN-2111-1
- USN-2112-1
- USN-2112-1
- USN-2114-1
- USN-2114-1
- USN-2115-1
- USN-2115-1
- USN-2116-1
- USN-2116-1
- USN-2128-1
- USN-2128-1
- USN-2129-1
- USN-2129-1
- RHSA-2018:1252
- RHSA-2018:1252
- https://bugzilla.redhat.com/show_bug.cgi?id=1028148
- https://bugzilla.redhat.com/show_bug.cgi?id=1028148
- https://github.com/torvalds/linux/commit/d049f74f2dbe71354d43d393ac3a188947811348
- https://github.com/torvalds/linux/commit/d049f74f2dbe71354d43d393ac3a188947811348
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.54
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.54
Modified: 2024-11-21
CVE-2013-3231
The llc_ui_recvmsg function in net/llc/af_llc.c in the Linux kernel before 3.9-rc7 does not initialize a certain length variable, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c77a4b9cffb6215a15196ec499490d116dfad181
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c77a4b9cffb6215a15196ec499490d116dfad181
- FEDORA-2013-6537
- FEDORA-2013-6537
- FEDORA-2013-6999
- FEDORA-2013-6999
- SUSE-SU-2013:1182
- SUSE-SU-2013:1182
- openSUSE-SU-2013:1187
- openSUSE-SU-2013:1187
- openSUSE-SU-2013:1971
- openSUSE-SU-2013:1971
- RHSA-2013:1645
- RHSA-2013:1645
- MDVSA-2013:176
- MDVSA-2013:176
- [oss-security] 20130414 Linux kernel: more net info leak fixes for v3.9
- [oss-security] 20130414 Linux kernel: more net info leak fixes for v3.9
- USN-1837-1
- USN-1837-1
- https://github.com/torvalds/linux/commit/c77a4b9cffb6215a15196ec499490d116dfad181
- https://github.com/torvalds/linux/commit/c77a4b9cffb6215a15196ec499490d116dfad181
- [linux-kernel] 20130414 Linux 3.9-rc7
- [linux-kernel] 20130414 Linux 3.9-rc7
Modified: 2024-11-21
CVE-2013-4162
The udp_v6_push_pending_frames function in net/ipv6/udp.c in the IPv6 implementation in the Linux kernel through 3.10.3 makes an incorrect function call for pending data, which allows local users to cause a denial of service (BUG and system crash) via a crafted application that uses the UDP_CORK option in a setsockopt system call.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8822b64a0fa64a5dd1dfcf837c5b0be83f8c05d1
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8822b64a0fa64a5dd1dfcf837c5b0be83f8c05d1
- SUSE-SU-2013:1473
- SUSE-SU-2013:1473
- SUSE-SU-2013:1474
- SUSE-SU-2013:1474
- openSUSE-SU-2013:1971
- openSUSE-SU-2013:1971
- RHSA-2013:1436
- RHSA-2013:1436
- RHSA-2013:1460
- RHSA-2013:1460
- RHSA-2013:1520
- RHSA-2013:1520
- 54148
- 54148
- 55055
- 55055
- [oss-security] 20130723 Re: CVE Request: Linux kernel: panic while pushing pending data out of an IPv6 socket with UDP_CORK enabled.
- [oss-security] 20130723 Re: CVE Request: Linux kernel: panic while pushing pending data out of an IPv6 socket with UDP_CORK enabled.
- 61411
- 61411
- USN-1938-1
- USN-1938-1
- USN-1939-1
- USN-1939-1
- USN-1941-1
- USN-1941-1
- USN-1942-1
- USN-1942-1
- USN-1943-1
- USN-1943-1
- USN-1944-1
- USN-1944-1
- USN-1945-1
- USN-1945-1
- USN-1946-1
- USN-1946-1
- USN-1947-1
- USN-1947-1
- https://bugzilla.redhat.com/show_bug.cgi?id=987627
- https://bugzilla.redhat.com/show_bug.cgi?id=987627
- https://github.com/torvalds/linux/commit/8822b64a0fa64a5dd1dfcf837c5b0be83f8c05d1
- https://github.com/torvalds/linux/commit/8822b64a0fa64a5dd1dfcf837c5b0be83f8c05d1
Modified: 2024-11-21
CVE-2013-4299
Interpretation conflict in drivers/md/dm-snap-persistent.c in the Linux kernel through 3.11.6 allows remote authenticated users to obtain sensitive information or modify data via a crafted mapping to a snapshot block device.
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e9c6a182649f4259db704ae15a91ac820e63b0ca
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=e9c6a182649f4259db704ae15a91ac820e63b0ca
- SUSE-SU-2015:0652
- SUSE-SU-2015:0652
- SUSE-SU-2015:0812
- SUSE-SU-2015:0812
- RHSA-2013:1436
- RHSA-2013:1436
- RHSA-2013:1449
- RHSA-2013:1449
- RHSA-2013:1450
- RHSA-2013:1450
- RHSA-2013:1460
- RHSA-2013:1460
- RHSA-2013:1490
- RHSA-2013:1490
- RHSA-2013:1519
- RHSA-2013:1519
- RHSA-2013:1520
- RHSA-2013:1520
- RHSA-2013:1783
- RHSA-2013:1783
- RHSA-2013:1860
- RHSA-2013:1860
- USN-2015-1
- USN-2015-1
- USN-2016-1
- USN-2016-1
- USN-2040-1
- USN-2040-1
- USN-2041-1
- USN-2041-1
- USN-2042-1
- USN-2042-1
- USN-2043-1
- USN-2043-1
- USN-2044-1
- USN-2044-1
- USN-2045-1
- USN-2045-1
- USN-2046-1
- USN-2046-1
- USN-2049-1
- USN-2049-1
- USN-2050-1
- USN-2050-1
- USN-2066-1
- USN-2066-1
- USN-2067-1
- USN-2067-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1004233
- https://bugzilla.redhat.com/show_bug.cgi?id=1004233
- https://github.com/torvalds/linux/commit/e9c6a182649f4259db704ae15a91ac820e63b0ca
- https://github.com/torvalds/linux/commit/e9c6a182649f4259db704ae15a91ac820e63b0ca
Modified: 2024-11-21
CVE-2013-4345
Off-by-one error in the get_prng_bytes function in crypto/ansi_cprng.c in the Linux kernel through 3.11.4 makes it easier for context-dependent attackers to defeat cryptographic protection mechanisms via multiple requests for small amounts of data, leading to improper management of the state of the consumed data.
- [linux-crypto] 20130917 [PATCH] ansi_cprng: Fix off by one error in non-block size request
- [linux-crypto] 20130917 [PATCH] ansi_cprng: Fix off by one error in non-block size request
- RHSA-2013:1449
- RHSA-2013:1449
- RHSA-2013:1490
- RHSA-2013:1490
- RHSA-2013:1645
- RHSA-2013:1645
- 62740
- 62740
- USN-2064-1
- USN-2064-1
- USN-2065-1
- USN-2065-1
- USN-2068-1
- USN-2068-1
- USN-2070-1
- USN-2070-1
- USN-2071-1
- USN-2071-1
- USN-2072-1
- USN-2072-1
- USN-2074-1
- USN-2074-1
- USN-2075-1
- USN-2075-1
- USN-2076-1
- USN-2076-1
- USN-2109-1
- USN-2109-1
- USN-2110-1
- USN-2110-1
- USN-2158-1
- USN-2158-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1007690
- https://bugzilla.redhat.com/show_bug.cgi?id=1007690
Modified: 2024-11-21
CVE-2013-4387
net/ipv6/ip6_output.c in the Linux kernel through 3.11.4 does not properly determine the need for UDP Fragmentation Offload (UFO) processing of small packets after the UFO queueing of a large packet, which allows remote attackers to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via network traffic that triggers a large response packet.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=2811ebac2521ceac84f2bdae402455baa6a7fb47
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=2811ebac2521ceac84f2bdae402455baa6a7fb47
- RHSA-2013:1490
- RHSA-2013:1490
- RHSA-2013:1645
- RHSA-2013:1645
- RHSA-2014:0284
- RHSA-2014:0284
- [oss-security] 20130928 Re: linux kernel memory corruption with ipv6 udp offloading
- [oss-security] 20130928 Re: linux kernel memory corruption with ipv6 udp offloading
- USN-2019-1
- USN-2019-1
- USN-2021-1
- USN-2021-1
- USN-2022-1
- USN-2022-1
- USN-2024-1
- USN-2024-1
- USN-2038-1
- USN-2038-1
- USN-2039-1
- USN-2039-1
- USN-2041-1
- USN-2041-1
- USN-2045-1
- USN-2045-1
- USN-2049-1
- USN-2049-1
- USN-2050-1
- USN-2050-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1011927
- https://bugzilla.redhat.com/show_bug.cgi?id=1011927
- https://github.com/torvalds/linux/commit/2811ebac2521ceac84f2bdae402455baa6a7fb47
- https://github.com/torvalds/linux/commit/2811ebac2521ceac84f2bdae402455baa6a7fb47
Modified: 2024-11-21
CVE-2013-4470
The Linux kernel before 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly initialize certain data structures, which allows local users to cause a denial of service (memory corruption and system crash) or possibly gain privileges via a crafted application that uses the UDP_CORK option in a setsockopt system call and sends both short and long packets, related to the ip_ufo_append_data function in net/ipv4/ip_output.c and the ip6_ufo_append_data function in net/ipv6/ip6_output.c.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c547dbf55d5f8cf615ccc0e7265e98db27d3fb8b
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c547dbf55d5f8cf615ccc0e7265e98db27d3fb8b
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e93b7d748be887cd7639b113ba7d7ef792a7efb9
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e93b7d748be887cd7639b113ba7d7ef792a7efb9
- SUSE-SU-2014:0459
- SUSE-SU-2014:0459
- RHSA-2013:1801
- RHSA-2013:1801
- RHSA-2014:0100
- RHSA-2014:0100
- RHSA-2014:0284
- RHSA-2014:0284
- [oss-security] 20131025 Re: CVE request: Linux kernel: net: memory corruption with UDP_CORK and UFO
- [oss-security] 20131025 Re: CVE request: Linux kernel: net: memory corruption with UDP_CORK and UFO
- 63359
- 63359
- USN-2040-1
- USN-2040-1
- USN-2042-1
- USN-2042-1
- USN-2043-1
- USN-2043-1
- USN-2044-1
- USN-2044-1
- USN-2046-1
- USN-2046-1
- USN-2049-1
- USN-2049-1
- USN-2050-1
- USN-2050-1
- USN-2066-1
- USN-2066-1
- USN-2067-1
- USN-2067-1
- USN-2069-1
- USN-2069-1
- USN-2073-1
- USN-2073-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1023477
- https://bugzilla.redhat.com/show_bug.cgi?id=1023477
- https://github.com/torvalds/linux/commit/c547dbf55d5f8cf615ccc0e7265e98db27d3fb8b
- https://github.com/torvalds/linux/commit/c547dbf55d5f8cf615ccc0e7265e98db27d3fb8b
- https://github.com/torvalds/linux/commit/e93b7d748be887cd7639b113ba7d7ef792a7efb9
- https://github.com/torvalds/linux/commit/e93b7d748be887cd7639b113ba7d7ef792a7efb9
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.12.bz2
- https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.12.bz2
Modified: 2024-11-21
CVE-2013-4588
Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability for (1) a getsockopt system call, related to the do_ip_vs_get_ctl function, or (2) a setsockopt system call, related to the do_ip_vs_set_ctl function.
- http://ftp.linux.org.uk/pub/linux/linux-2.6/ChangeLog-2.6.33
- http://ftp.linux.org.uk/pub/linux/linux-2.6/ChangeLog-2.6.33
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=04bcef2a83f40c6db24222b27a52892cba39dffb
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=04bcef2a83f40c6db24222b27a52892cba39dffb
- [oss-security] 20131115 Re: CVE request: Linux kernel: net: ipvs stack buffer overflow
- [oss-security] 20131115 Re: CVE request: Linux kernel: net: ipvs stack buffer overflow
- 63744
- 63744
- USN-2064-1
- USN-2064-1
- USN-2065-1
- USN-2065-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1030800
- https://bugzilla.redhat.com/show_bug.cgi?id=1030800
- https://github.com/torvalds/linux/commit/04bcef2a83f40c6db24222b27a52892cba39dffb
- https://github.com/torvalds/linux/commit/04bcef2a83f40c6db24222b27a52892cba39dffb
Modified: 2024-11-21
CVE-2013-6367
The apic_get_tmcct function in arch/x86/kvm/lapic.c in the KVM subsystem in the Linux kernel through 3.12.5 allows guest OS users to cause a denial of service (divide-by-zero error and host OS crash) via crafted modifications of the TMICT value.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b963a22e6d1a266a67e9eecc88134713fd54775c
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b963a22e6d1a266a67e9eecc88134713fd54775c
- openSUSE-SU-2014:0204
- openSUSE-SU-2014:0204
- openSUSE-SU-2014:0205
- openSUSE-SU-2014:0205
- openSUSE-SU-2014:0247
- openSUSE-SU-2014:0247
- RHSA-2013:1801
- RHSA-2013:1801
- RHSA-2014:0163
- RHSA-2014:0163
- RHSA-2014:0284
- RHSA-2014:0284
- [oss-security] 20131212 Re: [vs-plain] kvm issues
- [oss-security] 20131212 Re: [vs-plain] kvm issues
- 64270
- 64270
- USN-2109-1
- USN-2109-1
- USN-2110-1
- USN-2110-1
- USN-2113-1
- USN-2113-1
- USN-2117-1
- USN-2117-1
- USN-2128-1
- USN-2128-1
- USN-2129-1
- USN-2129-1
- USN-2135-1
- USN-2135-1
- USN-2136-1
- USN-2136-1
- USN-2138-1
- USN-2138-1
- USN-2139-1
- USN-2139-1
- USN-2141-1
- USN-2141-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1032207
- https://bugzilla.redhat.com/show_bug.cgi?id=1032207
- https://github.com/torvalds/linux/commit/b963a22e6d1a266a67e9eecc88134713fd54775c
- https://github.com/torvalds/linux/commit/b963a22e6d1a266a67e9eecc88134713fd54775c
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.54
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.54
Modified: 2024-11-21
CVE-2013-6368
The KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges or cause a denial of service (system crash) via a VAPIC synchronization operation involving a page-end address.
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fda4e2e85589191b123d31cdc21fd33ee70f50fd
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=fda4e2e85589191b123d31cdc21fd33ee70f50fd
- openSUSE-SU-2014:0204
- openSUSE-SU-2014:0204
- openSUSE-SU-2014:0205
- openSUSE-SU-2014:0205
- openSUSE-SU-2014:0247
- openSUSE-SU-2014:0247
- RHSA-2013:1801
- RHSA-2013:1801
- RHSA-2014:0163
- RHSA-2014:0163
- RHSA-2014:0284
- RHSA-2014:0284
- [oss-security] 20131212 Re: [vs-plain] kvm issues
- [oss-security] 20131212 Re: [vs-plain] kvm issues
- 64291
- 64291
- USN-2113-1
- USN-2113-1
- USN-2117-1
- USN-2117-1
- USN-2133-1
- USN-2133-1
- USN-2134-1
- USN-2134-1
- USN-2135-1
- USN-2135-1
- USN-2136-1
- USN-2136-1
- USN-2138-1
- USN-2138-1
- USN-2139-1
- USN-2139-1
- USN-2141-1
- USN-2141-1
- https://bugzilla.redhat.com/show_bug.cgi?id=1032210
- https://bugzilla.redhat.com/show_bug.cgi?id=1032210
- https://github.com/torvalds/linux/commit/fda4e2e85589191b123d31cdc21fd33ee70f50fd
- https://github.com/torvalds/linux/commit/fda4e2e85589191b123d31cdc21fd33ee70f50fd
Modified: 2023-11-07
CVE-2013-6405
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2013-7263, CVE-2013-7264, CVE-2013-7265, CVE-2013-7281. Reason: This candidate is a duplicate of CVE-2013-7263, CVE-2013-7264, CVE-2013-7265, and CVE-2013-7281. Notes: All CVE users should reference CVE-2013-7263, CVE-2013-7264, CVE-2013-7265, and/or CVE-2013-7281 instead of this candidate. All references and descriptions in this candidate have been removed to prevent accidental usage