CVE-2013-0914
published 2013-03-22CVE-2013-0914: The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation…
PriorityP412low3.6CVSS 2.0
AVLACLAuNCPIPAN
EPSS
0.46%
37.2th percentile
The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted application containing a sigaction system call.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.41-1 (bookworm) | linux 3.2.41-1 (bookworm) |
| linux | linux_kernel | <= 3.8.3 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
| linux | linux_kernel | >= 0 < 3.2.41-1 | 3.2.41-1 |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv3.6LOW
vendor_ubuntu6.2MEDIUM
vendor_debian3.6LOW
vendor_redhat3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-chr6-8347-2cjg: The flush_signal_handlers function in kernel/signal
ghsa_unreviewed·2022-05-17
CVE-2013-0914 [LOW] GHSA-chr6-8347-2cjg: The flush_signal_handlers function in kernel/signal
The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted application containing a sigaction system call.
OSV
CVE-2013-0914: The flush_signal_handlers function in kernel/signal
osv·2013-03-22·CVSS 3.6
CVE-2013-0914 [LOW] CVE-2013-0914: The flush_signal_handlers function in kernel/signal
The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted application containing a sigaction system call.
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2013-04-09·CVSS 1.9
CVE-2012-6537 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered several errors in the Linux kernel's xfrm_user
implementation. A local attacker could exploit these flaws to examine parts
of kernel memory. (CVE-2012-6537)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible t
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 3.6
CVE-2013-0914 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2013-1792)
Mathias
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 6.2
CVE-2013-0228 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-0228)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem.
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 6.2
CVE-2013-0228 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-0228)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesy
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 3.6
CVE-2013-0914 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2013-1792)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 1.9
CVE-2012-6537 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered several errors in the Linux kernel's xfrm_user
implementation. A local attacker could exploit these flaws to examine parts
of kernel memory. (CVE-2012-6537)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by p
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 6.2
CVE-2013-0228 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-0228)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2013-04-04·CVSS 3.6
CVE-2013-0914 [LOW] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to bypass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
bypass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discovered in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-02·CVSS 3.6
CVE-2013-0914 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2013-1792)
Instruct
Red Hat
Kernel: sa_restorer information leak
vendor_redhat·2013-03-11·CVSS 3.6
CVE-2013-0914 [LOW] Kernel: sa_restorer information leak
Kernel: sa_restorer information leak
The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted application containing a sigaction system call.
Statement: This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2 may address this issue.
Debian
CVE-2013-0914: linux - The flush_signal_handlers function in kernel/signal.c in the Linux kernel before...
vendor_debian·2013·CVSS 3.6
CVE-2013-0914 [LOW] CVE-2013-0914: linux - The flush_signal_handlers function in kernel/signal.c in the Linux kernel before...
The flush_signal_handlers function in kernel/signal.c in the Linux kernel before 3.8.4 preserves the value of the sa_restorer field across an exec operation, which makes it easier for local users to bypass the ASLR protection mechanism via a crafted application containing a sigaction system call.
Scope: local
bookworm: resolved (fixed in 3.2.41-1)
bullseye: resolved (fixed in 3.2.41-1)
forky: resolved (fixed in 3.2.41-1)
sid: resolved (fixed in 3.2.41-1)
trixie: resolved (fixed in 3.2.41-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-0914 Kernel: sa_restorer information leak [fedora-all]
bugzilla·2013-03-12·CVSS 3.6
CVE-2013-0914 [LOW] CVE-2013-0914 Kernel: sa_restorer information leak [fedora-all]
CVE-2013-0914 Kernel: sa_restorer information leak [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affects multiple
Bugzilla
CVE-2013-0914 Kernel: sa_restorer information leak
bugzilla·2013-03-12·CVSS 3.6
CVE-2013-0914 [LOW] CVE-2013-0914 Kernel: sa_restorer information leak
CVE-2013-0914 Kernel: sa_restorer information leak
Linux kernel is vulnerable to an information leakage flaw. This occurs when
a process calls routine - sigaction() - to access - sa_restorer - parameter.
This parameter points to an address that belongs to its parent process'
address space.
A user could use this flaw to infer address layout of a process.
Reference:
-> https://lkml.org/lkml/2013/3/11/498
-> http://www.openwall.com/lists/oss-security/2013/03/11/8
Discussion:
Upstream fix
-> http://www.spinics.net/lists/mm-commits/msg95304.html
---
Statement:
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2 may address this issue
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=2ca39528c01a933f6689cd6505ce65bd6d68a530http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1051.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.4http://www.mandriva.com/security/advisories?name=MDVSA-2013:176http://www.openwall.com/lists/oss-security/2013/03/11/8http://www.ubuntu.com/usn/USN-1787-1http://www.ubuntu.com/usn/USN-1788-1http://www.ubuntu.com/usn/USN-1792-1http://www.ubuntu.com/usn/USN-1793-1http://www.ubuntu.com/usn/USN-1794-1http://www.ubuntu.com/usn/USN-1795-1http://www.ubuntu.com/usn/USN-1796-1http://www.ubuntu.com/usn/USN-1797-1http://www.ubuntu.com/usn/USN-1798-1https://bugzilla.redhat.com/show_bug.cgi?id=920499https://github.com/torvalds/linux/commit/2ca39528c01a933f6689cd6505ce65bd6d68a530http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=2ca39528c01a933f6689cd6505ce65bd6d68a530http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1051.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.4http://www.mandriva.com/security/advisories?name=MDVSA-2013:176http://www.openwall.com/lists/oss-security/2013/03/11/8http://www.ubuntu.com/usn/USN-1787-1http://www.ubuntu.com/usn/USN-1788-1http://www.ubuntu.com/usn/USN-1792-1http://www.ubuntu.com/usn/USN-1793-1http://www.ubuntu.com/usn/USN-1794-1http://www.ubuntu.com/usn/USN-1795-1http://www.ubuntu.com/usn/USN-1796-1http://www.ubuntu.com/usn/USN-1797-1http://www.ubuntu.com/usn/USN-1798-1https://bugzilla.redhat.com/show_bug.cgi?id=920499https://github.com/torvalds/linux/commit/2ca39528c01a933f6689cd6505ce65bd6d68a530
2013-03-22
Published