CVE-2013-0913
published 2013-03-18CVE-2013-0913: Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.56%
43.2th percentile
Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted application that triggers many relocation copies, and potentially leads to a race condition.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.41-2 (bookworm) | linux 3.2.41-2 (bookworm) |
| linux | linux_kernel | >= 0 < 3.2.41-2 | 3.2.41-2 |
| linux | linux_kernel | >= 0 < 3.2.41-2 | 3.2.41-2 |
| linux | linux_kernel | >= 0 < 3.2.41-2 | 3.2.41-2 |
| linux | linux_kernel | >= 0 < 3.2.41-2 | 3.2.41-2 |
| linux | linux_kernel | >= 2.6.37 < 3.0.71 | 3.0.71 |
| linux | linux_kernel | >= 3.1 < 3.2.42 | 3.2.42 |
| linux | linux_kernel | >= 3.3 < 3.4.38 | 3.4.38 |
| linux | linux_kernel | >= 3.5 < 3.8.5 | 3.8.5 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-05-02·CVSS 1.9
CVE-2012-6548 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's UDF
file system implementation. A local user could exploit this flaw to examine
some of the kernel's heap memory. (CVE-2012-6548)
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
An integer overflow was discovered in the Direct Rendering Manager (DRM)
subsystem for the i915 video driver in the Linux kernel. A local user could
exploit this flaw to cause a denial of service (crash) or potentially
escalate privileges. (CVE-2013-0913)
Andrew Honig discovered a flaw in guest OS ti
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-05-02·CVSS 1.9
CVE-2012-6548 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's UDF
file system implementation. A local user could exploit this flaw to examine
some of the kernel's heap memory. (CVE-2012-6548)
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
An integer overflow was discovered in the Direct Rendering Manager (DRM)
subsystem for the i915 video driver in the Linux kernel. A local user could
exploit this flaw to cause a denial of service (crash) or potentially
escalate privileges. (CVE-2013-0913)
A format-string bug was discovered in
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-05-01·CVSS 1.9
CVE-2012-6548 [LOW] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's UDF
file system implementation. A local user could exploit this flaw to examine
some of the kernel's heap memory. (CVE-2012-6548)
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
An integer overflow was discovered in the Direct Rendering Manager (DRM)
subsystem for the i915 video driver in the Linux kernel. A local user could
exploit this flaw to cause a denial of service (crash) or potentially
escalate privileges. (CVE-2013-0913)
Andrew Honig discovered a flaw
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-05-01·CVSS 1.9
CVE-2012-6548 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered an information leak in the Linux kernel's UDF
file system implementation. A local user could exploit this flaw to examine
some of the kernel's heap memory. (CVE-2012-6548)
Mathias Krause discovered an information leak in the Linux kernel's ISO
9660 CDROM file system driver. A local user could exploit this flaw to
examine some of the kernel's heap memory. (CVE-2012-6549)
An integer overflow was discovered in the Direct Rendering Manager (DRM)
subsystem for the i915 video driver in the Linux kernel. A local user could
exploit this flaw to cause a denial of service (crash) or potentially
escalate privileges. (CVE-2013-0913)
Andrew Honig discovered a use after f
Red Hat
Kernel: drm/i915: heap writing overflow
vendor_redhat·2013-03-11·CVSS 7.2
CVE-2013-0913 [HIGH] Kernel: drm/i915: heap writing overflow
Kernel: drm/i915: heap writing overflow
Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted application that triggers many relocation copies, and potentially leads to a race condition.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise MRG 2 may addres
Debian
CVE-2013-0913: linux - Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 drive...
vendor_debian·2013·CVSS 7.2
CVE-2013-0913 [HIGH] CVE-2013-0913: linux - Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 drive...
Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted application that triggers many relocation copies, and potentially leads to a race condition.
Scope: local
bookworm: resolved (fixed in 3.2.41-2)
bullseye: resolved (fixed in 3.2.41-2)
forky: resolved (fixed in 3.2.41-2)
sid: resolved (fixed in 3.2.41-2)
trixie: resolved (fixed in 3.2.41-2)
GHSA
GHSA-vxj5-2742-4q53: Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer
ghsa_unreviewed·2022-05-17
CVE-2013-0913 [HIGH] GHSA-vxj5-2742-4q53: Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer
Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted application that triggers many relocation copies, and potentially leads to a race condition.
OSV
CVE-2013-0913: Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer
osv·2013-03-18·CVSS 7.2
CVE-2013-0913 [HIGH] CVE-2013-0913: Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer
Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted application that triggers many relocation copies, and potentially leads to a race condition.
Kernel
drm/i915: bounds check execbuffer relocation count
kernel_security·2013-03-11·CVSS 7.2
CVE-2013-0913 [HIGH] drm/i915: bounds check execbuffer relocation count
drm/i915: bounds check execbuffer relocation count
It is possible to wrap the counter used to allocate the buffer for
relocation copies. This could lead to heap writing overflows.
CVE-2013-0913
v3: collapse test, improve comment
v2: move check into validate_exec_list
Signed-off-by: Kees Cook
Reported-by: Pinkie Pie
Cc: [email protected]
Reviewed-by: Chris Wilson
Signed-off-by: Daniel Vetter
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0913 Kernel: drm/i915: heap writing overflow
bugzilla·2013-03-12·CVSS 7.2
CVE-2013-0913 [HIGH] CVE-2013-0913 Kernel: drm/i915: heap writing overflow
CVE-2013-0913 Kernel: drm/i915: heap writing overflow
Linux kernel built with Direct Rendering Manager(DRM) i915 driver for the
the Direct Rendering Infrastructure(DRI) introduced by XFree86 4.0, is
vulnerable to a heap overflow flaw.
An user/program with access to the DRM driver could use this flaw to crash
the kernel, resulting in DoS or possibly escalate privileges.
Reference:
-> https://lkml.org/lkml/2013/3/11/501
-> http://www.openwall.com/lists/oss-security/2013/03/11/6
Discussion:
Statement:
This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise MRG 2 may address
Bugzilla
CVE-2013-0913 Kernel: drm/i915: heap writing overflow [fedora-all]
bugzilla·2013-03-12·CVSS 7.2
CVE-2013-0913 [HIGH] CVE-2013-0913 Kernel: drm/i915: heap writing overflow [fedora-all]
CVE-2013-0913 Kernel: drm/i915: heap writing overflow [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multip
http://git.chromium.org/gitweb/?p=chromiumos/third_party/kernel.git%3Ba=commit%3Bh=c79efdf2b7f68f985922a8272d64269ecd490477http://googlechromereleases.blogspot.com/2013/03/stable-channel-update-for-chrome-os_15.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://openwall.com/lists/oss-security/2013/03/11/6http://openwall.com/lists/oss-security/2013/03/13/9http://openwall.com/lists/oss-security/2013/03/14/22http://rhn.redhat.com/errata/RHSA-2013-0744.htmlhttp://www.ubuntu.com/usn/USN-1809-1http://www.ubuntu.com/usn/USN-1811-1http://www.ubuntu.com/usn/USN-1812-1http://www.ubuntu.com/usn/USN-1813-1http://www.ubuntu.com/usn/USN-1814-1https://bugzilla.redhat.com/show_bug.cgi?id=920471https://code.google.com/p/chromium-os/issues/detail?id=39733https://gerrit.chromium.org/gerrit/45118https://lkml.org/lkml/2013/3/11/501http://git.chromium.org/gitweb/?p=chromiumos/third_party/kernel.git%3Ba=commit%3Bh=c79efdf2b7f68f985922a8272d64269ecd490477http://googlechromereleases.blogspot.com/2013/03/stable-channel-update-for-chrome-os_15.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://openwall.com/lists/oss-security/2013/03/11/6http://openwall.com/lists/oss-security/2013/03/13/9http://openwall.com/lists/oss-security/2013/03/14/22http://rhn.redhat.com/errata/RHSA-2013-0744.htmlhttp://www.ubuntu.com/usn/USN-1809-1http://www.ubuntu.com/usn/USN-1811-1http://www.ubuntu.com/usn/USN-1812-1http://www.ubuntu.com/usn/USN-1813-1http://www.ubuntu.com/usn/USN-1814-1https://bugzilla.redhat.com/show_bug.cgi?id=920471https://code.google.com/p/chromium-os/issues/detail?id=39733https://gerrit.chromium.org/gerrit/45118https://lkml.org/lkml/2013/3/11/501
2013-03-18
Published