CVE-2013-0310
published 2013-02-22CVE-2013-0310: The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer…
PriorityP417medium6.6CVSS 2.0
AVLACMAuSCCICAC
EPSS
0.32%
23.7th percentile
The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call.
Affected
116 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.11.7-1 (bookworm) | linux 3.11.7-1 (bookworm) |
| debian | linux | < linux 3.2.29-1 (bookworm) | linux 3.2.29-1 (bookworm) |
| linux | linux_kernel | < 3.11.7 | 3.11.7 |
| linux | linux_kernel | <= 3.4.7 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.06.6MEDIUMAV:L/AC:M/Au:S/C:C/I:C/A:C
osv6.6MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian6.6MEDIUM
vendor_redhat6.6MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: disabled CONFIG_NETLABEL in cipso_v4_validate in include/net/cipso_ipv4.h leads to denial of service
vendor_redhat·2013-10-19·CVSS 6.6
CVE-2013-7470 [MEDIUM] CWE-119 kernel: disabled CONFIG_NETLABEL in cipso_v4_validate in include/net/cipso_ipv4.h leads to denial of service
kernel: disabled CONFIG_NETLABEL in cipso_v4_validate in include/net/cipso_ipv4.h leads to denial of service
cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-alt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 7) - Not affected
Package: kernel (Red Hat Enterprise Linux 8) - Not affected
Package: kernel-rt (Red Hat Enterprise Linux 8) - Not
Red Hat
kernel: net: CIPSO_V4_TAG_LOCAL tag NULL pointer dereference
vendor_redhat·2013-02-19·CVSS 6.6
CVE-2013-0310 [MEDIUM] CWE-476 kernel: net: CIPSO_V4_TAG_LOCAL tag NULL pointer dereference
kernel: net: CIPSO_V4_TAG_LOCAL tag NULL pointer dereference
The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call.
Statement: This issue did affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 6.
This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-7470: linux - cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7,...
vendor_debian·2013·CVSS 6.6
CVE-2013-7470 [MEDIUM] CVE-2013-7470: linux - cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7,...
cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310.
Scope: local
bookworm: resolved (fixed in 3.11.7-1)
bullseye: resolved (fixed in 3.11.7-1)
forky: resolved (fixed in 3.11.7-1)
sid: resolved (fixed in 3.11.7-1)
trixie: resolved (fixed in 3.11.7-1)
Debian
CVE-2013-0310: linux - The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel befo...
vendor_debian·2013·CVSS 6.6
CVE-2013-0310 [MEDIUM] CVE-2013-0310: linux - The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel befo...
The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call.
Scope: local
bookworm: resolved (fixed in 3.2.29-1)
bullseye: resolved (fixed in 3.2.29-1)
forky: resolved (fixed in 3.2.29-1)
sid: resolved (fixed in 3.2.29-1)
trixie: resolved (fixed in 3.2.29-1)
Ubuntu
Linux kernel (EC2) vulnerability
vendor_ubuntu·2012-12-04·CVSS 4.7
CVE-2012-4565 [MEDIUM] Linux kernel (EC2) vulnerability
Title: Linux kernel (EC2) vulnerability
Summary: The system could be made to run programs as an administrator.
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP
device driver. A local user could exploit this flaw to examine part of the
kernel's stack memory. (CVE-2012-6547)
Denys Fedoryshchenko discovered a flaw in the Linux kernel's TCP receive
processing for IPv4. A remote attacker could exploit this flaw to cause a
denial of service (kernel resource consumption) via a flood of SYN+FIN TCP
packets. (CVE-2012-6638)
A flaw was discovered in the requeuing of futexes in the Linux kernel.
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-11-30·CVSS 4.7
CVE-2012-4565 [MEDIUM] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
Rodrigo Freire discovered a flaw in the Linux kernel's TCP illinois
congestion control algorithm. A local attacker could use this to cause a
denial of service. (CVE-2012-4565)
Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP
device driver. A local user could exploit this flaw to examine part of the
kernel's stack memory. (CVE-2012-6547)
Denys Fedoryshchenko discovered a flaw in the Linux kernel's TCP receive
processing for IPv4. A remote attacker could exploit this flaw to cause a
denial of service (kernel resource consumption) via a flood of SYN+FIN TCP
packets. (CVE-2012-6638)
A flaw was discovered in the requeuing of futexes in the Linux kernel. A
local
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2012-09-21·CVSS 7.8
CVE-2012-3412 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP
device driver. A local user could exploit this flaw to examine part of the
kernel's stack memory. (CVE-2012-6547)
A flaw was discovered in the requeuing of futexes in the Linux kernel. A
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2012-09-21·CVSS 7.8
CVE-2012-3412 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hutchings reported a flaw in the Linux kernel with some network drivers
that support TSO (TCP segment offload). A local or peer user could exploit
this flaw to to cause a denial of service. (CVE-2012-3412)
Jay Fenlason and Doug Ledford discovered a bug in the Linux kernel
implementation of RDS sockets. A local unprivileged user could potentially
use this flaw to read privileged information from the kernel.
(CVE-2012-3430)
Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP
device driver. A local user could exploit this flaw to examine part of the
kernel's stack memory. (CVE-2012-6547)
A flaw was discovered in the requeuing of futexes in the Linux kernel. A
local u
Ubuntu
Linux kernel (Oneiric backport) vulnerability
vendor_ubuntu·2012-09-10·CVSS 4.4
CVE-2012-2372 [MEDIUM] Linux kernel (Oneiric backport) vulnerability
Title: Linux kernel (Oneiric backport) vulnerability
Summary: The system could be made to crash under certain conditions.
A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS)
protocol implementation. A local, unprivileged user could use this flaw to
cause a denial of service. (CVE-2012-2372)
Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP
device driver. A local user could exploit this flaw to examine part of the
kernel's stack memory. (CVE-2012-6547)
A flaw was found in Linux kernel's validation of CIPSO (Common IP Security
Option) options set from userspace. A local user that can set a socket's
CIPSO options could exploit this flaw to cause a denial of service (crash
the system). (CVE-2013-0310)
Instructions: After a standard system updat
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2012-09-07·CVSS 4.4
CVE-2012-2372 [MEDIUM] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to crash under certain conditions.
A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS)
protocol implementation. A local, unprivileged user could use this flaw to
cause a denial of service. (CVE-2012-2372)
Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP
device driver. A local user could exploit this flaw to examine part of the
kernel's stack memory. (CVE-2012-6547)
A flaw was found in Linux kernel's validation of CIPSO (Common IP Security
Option) options set from userspace. A local user that can set a socket's
CIPSO options could exploit this flaw to cause a denial of service (crash
the system). (CVE-2013-0310)
Instructions: After a standard system update you need
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2012-09-05·CVSS 4.4
CVE-2012-2372 [MEDIUM] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash under certain conditions.
A flaw was found in the Linux kernel's Reliable Datagram Sockets (RDS)
protocol implementation. A local, unprivileged user could use this flaw to
cause a denial of service. (CVE-2012-2372)
Mathias Krause discovered an information leak in the Linux kernel's TUN/TAP
device driver. A local user could exploit this flaw to examine part of the
kernel's stack memory. (CVE-2012-6547)
A flaw was found in Linux kernel's validation of CIPSO (Common IP Security
Option) options set from userspace. A local user that can set a socket's
CIPSO options could exploit this flaw to cause a denial of service (crash
the system). (CVE-2013-0310)
Instructions: After a standard system update you need to reboo
GHSA
GHSA-7jjv-m4pq-hv68: The cipso_v4_validate function in net/ipv4/cipso_ipv4
ghsa_unreviewed·2022-05-05
CVE-2013-0310 [MEDIUM] CWE-119 GHSA-7jjv-m4pq-hv68: The cipso_v4_validate function in net/ipv4/cipso_ipv4
The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call.
GHSA
GHSA-fvc2-9q3j-5cg7: cipso_v4_validate in include/net/cipso_ipv4
ghsa_unreviewed·2022-05-05·CVSS 6.6
CVE-2013-7470 [MEDIUM] CWE-400 GHSA-fvc2-9q3j-5cg7: cipso_v4_validate in include/net/cipso_ipv4
cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310.
OSV
CVE-2013-7470: cipso_v4_validate in include/net/cipso_ipv4
osv·2019-04-23·CVSS 6.6
CVE-2013-7470 [MEDIUM] CVE-2013-7470: cipso_v4_validate in include/net/cipso_ipv4
cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310.
OSV
CVE-2013-0310: The cipso_v4_validate function in net/ipv4/cipso_ipv4
osv·2013-02-22·CVSS 6.6
CVE-2013-0310 [MEDIUM] CVE-2013-0310: The cipso_v4_validate function in net/ipv4/cipso_ipv4
The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel before 3.4.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an IPOPT_CIPSO IP_OPTIONS setsockopt system call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-7470 kernel: disabled CONFIG_NETLABEL in cipso_v4_validate in include/net/cipso_ipv4.h leads to denial of service
bugzilla·2019-05-03·CVSS 6.6
CVE-2013-7470 [MEDIUM] CVE-2013-7470 kernel: disabled CONFIG_NETLABEL in cipso_v4_validate in include/net/cipso_ipv4.h leads to denial of service
CVE-2013-7470 kernel: disabled CONFIG_NETLABEL in cipso_v4_validate in include/net/cipso_ipv4.h leads to denial of service
cipso_v4_validate in include/net/cipso_ipv4.h in the Linux kernel before 3.11.7, when CONFIG_NETLABEL is disabled, allows attackers to cause a denial of service (infinite loop and crash), as demonstrated by icmpsic, a different vulnerability than CVE-2013-0310.
Upstream patch:
https://github.com/torvalds/linux/commit/f2e5ddcc0d12f9c4c7b254358ad245c9dddce13b
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=f2e5ddcc0d12f9c4c7b254358ad245c9dddce13b
References:
https://cdn.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.11.7
Bugzilla
CVE-2013-0310 kernel: net: CIPSO_V4_TAG_LOCAL tag NULL pointer dereference
bugzilla·2013-02-20·CVSS 6.6
CVE-2013-0310 [MEDIUM] CVE-2013-0310 kernel: net: CIPSO_V4_TAG_LOCAL tag NULL pointer dereference
CVE-2013-0310 kernel: net: CIPSO_V4_TAG_LOCAL tag NULL pointer dereference
The skb argument to cipso_v4_validate() is NULL when called via the setsockopt() syscall. An local user able to set CIPSO IP options on the socket could use this flaw to crash the system.
Upstream fix:
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=89d7ae34cdda4195809a5a987f697a517a2a3177
Discussion:
Statement:
This issue did affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 6.
This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
---
This issue has been addressed in following products:
Red Hat Enterprise Linux 6
Via RHSA-2013:0496 https://rhn.redhat.com/errata/RHSA-2013-0496.html
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=89d7ae34cdda4195809a5a987f697a517a2a3177http://rhn.redhat.com/errata/RHSA-2013-0496.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.8http://www.openwall.com/lists/oss-security/2013/02/20/5https://bugzilla.redhat.com/show_bug.cgi?id=912900https://github.com/torvalds/linux/commit/89d7ae34cdda4195809a5a987f697a517a2a3177http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=89d7ae34cdda4195809a5a987f697a517a2a3177http://rhn.redhat.com/errata/RHSA-2013-0496.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.8http://www.openwall.com/lists/oss-security/2013/02/20/5https://bugzilla.redhat.com/show_bug.cgi?id=912900https://github.com/torvalds/linux/commit/89d7ae34cdda4195809a5a987f697a517a2a3177
2013-02-22
Published