CVE-2013-0310Improper Restriction of Operations within the Bounds of a Memory Buffer in Kernel

Severity
6.6MEDIUMNVD
NVD5.9
EPSS
0.1%
top 81.58%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 22
Latest updateMay 5

Description

The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call.

CVSS vector

AV:L/AC:M/C:C/I:C/A:CExploitability: 2.7 | Impact: 10.0

Affected Packages3 packages

NVDlinux/linux_kernel< 3.11.7+104
Debianlinux/linux_kernel< 3.2.29-1+7
debiandebian/linux< linux 3.11.7-1 (bookworm)+1

Also affects: Enterprise Linux 6.0

🔴Vulnerability Details

4
GHSA
GHSA-7jjv-m4pq-hv68: The cipso_v4_validate function in net/ipv4/cipso_ipv42022-05-05
GHSA
GHSA-fvc2-9q3j-5cg7: cipso_v4_validate in include/net/cipso_ipv42022-05-05
OSV
CVE-2013-7470: cipso_v4_validate in include/net/cipso_ipv42019-04-23
OSV
CVE-2013-0310: The cipso_v4_validate function in net/ipv4/cipso_ipv42013-02-22

📋Vendor Advisories

11
Red Hat
kernel: disabled CONFIG_NETLABEL in cipso_v4_validate in include/net/cipso_ipv4.h leads to denial of service2013-10-19
Red Hat
kernel: net: CIPSO_V4_TAG_LOCAL tag NULL pointer dereference2013-02-19
Debian
CVE-2013-7470: linux - cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7,...2013
Debian
CVE-2013-0310: linux - The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel befo...2013
Ubuntu
Linux kernel (EC2) vulnerability2012-12-04

💬Community

2
Bugzilla
CVE-2013-7470 kernel: disabled CONFIG_NETLABEL in cipso_v4_validate in include/net/cipso_ipv4.h leads to denial of service2019-05-03
Bugzilla
CVE-2013-0310 kernel: net: CIPSO_V4_TAG_LOCAL tag NULL pointer dereference2013-02-20