CVE-2013-1059
published 2013-07-08CVE-2013-1059: net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
4.55%
90.6th percentile
net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an auth_reply message that triggers an attempted build_request operation.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 3.10.1-1 (bookworm) | linux 3.10.1-1 (bookworm) |
| linux | linux_kernel | < 3.0.86 | 3.0.86 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.10.1-1 | 3.10.1-1 |
| linux | linux_kernel | >= 0 < 3.10.1-1 | 3.10.1-1 |
| linux | linux_kernel | >= 0 < 3.10.1-1 | 3.10.1-1 |
| linux | linux_kernel | >= 0 < 3.10.1-1 | 3.10.1-1 |
| linux | linux_kernel | >= 3.1 < 3.2.49 | 3.2.49 |
| linux | linux_kernel | >= 3.3 < 3.4.53 | 3.4.53 |
| linux | linux_kernel | >= 3.5 < 3.9.10 | 3.9.10 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-j425-pcfw-2hmg: net/ceph/auth_none
ghsa_unreviewed·2022-05-17
CVE-2013-1059 [HIGH] CWE-476 GHSA-j425-pcfw-2hmg: net/ceph/auth_none
net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an auth_reply message that triggers an attempted build_request operation.
OSV
CVE-2013-1059: net/ceph/auth_none
osv·2013-07-08·CVSS 7.8
CVE-2013-1059 [HIGH] CVE-2013-1059: net/ceph/auth_none
net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an auth_reply message that triggers an attempted build_request operation.
Kernel
libceph: Fix NULL pointer dereference in auth client code
kernel_security·2013-06-20·CVSS 7.8
CVE-2013-1059 [HIGH] libceph: Fix NULL pointer dereference in auth client code
libceph: Fix NULL pointer dereference in auth client code
A malicious monitor can craft an auth reply message that could cause a
NULL function pointer dereference in the client's kernel.
To prevent this, the auth_none protocol handler needs an empty
ceph_auth_client_ops->build_request() function.
CVE-2013-1059
Signed-off-by: Tyler Hicks
Reported-by: Chanam Park
Reviewed-by: Seth Arnold
Reviewed-by: Sage Weil
Cc: [email protected]
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (CVE-2013-1060)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (CVE-2013-1060)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local us
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local use
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local user with admini
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local user wit
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local user with admini
Red Hat
Kernel: libceph: Fix NULL pointer dereference in auth client code
vendor_redhat·2013-07-01·CVSS 7.8
CVE-2013-1059 [HIGH] CWE-476 Kernel: libceph: Fix NULL pointer dereference in auth client code
Kernel: libceph: Fix NULL pointer dereference in auth client code
net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an auth_reply message that triggers an attempted build_request operation.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-1059: linux - net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to...
vendor_debian·2013·CVSS 7.8
CVE-2013-1059 [HIGH] CVE-2013-1059: linux - net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to...
net/ceph/auth_none.c in the Linux kernel through 3.10 allows remote attackers to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an auth_reply message that triggers an attempted build_request operation.
Scope: local
bookworm: resolved (fixed in 3.10.1-1)
bullseye: resolved (fixed in 3.10.1-1)
forky: resolved (fixed in 3.10.1-1)
sid: resolved (fixed in 3.10.1-1)
trixie: resolved (fixed in 3.10.1-1)
No detection rules found.
No public exploits indexed.
Bugzilla
kernel: CVE-2013-1059 Kernel: libceph: Fix NULL pointer dereference in auth client code [fedora-all]
bugzilla·2013-07-02·CVSS 7.8
CVE-2013-1059 [HIGH] kernel: CVE-2013-1059 Kernel: libceph: Fix NULL pointer dereference in auth client code [fedora-all]
kernel: CVE-2013-1059 Kernel: libceph: Fix NULL pointer dereference in auth client code [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Plea
Bugzilla
CVE-2013-1059 Kernel: libceph: Fix NULL pointer dereference in auth client code
bugzilla·2013-06-24·CVSS 7.8
CVE-2013-1059 [HIGH] CVE-2013-1059 Kernel: libceph: Fix NULL pointer dereference in auth client code
CVE-2013-1059 Kernel: libceph: Fix NULL pointer dereference in auth client code
Linux kernel built with the Ceph core library(CONFIG_CEPH_LIB) support is
vulnerable to a NULL pointer dereference flaw. It could occur while handling
auth_reply messages from a CEPH client.
A remote user/program could use this flaw to crash the system, resulting in
denial of service.
References:
http://hkpco.kr/advisory/CVE-2013-1059.txt
Discussion:
Statement:
This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 980341]
---
Created attachment 767633
Proposed patch
---
(In reply to Petr Matousek from comment #3)
> Created attachment 767633 [
http://hkpco.kr/advisory/CVE-2013-1059.txthttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://www.openwall.com/lists/oss-security/2013/07/09/7http://www.ubuntu.com/usn/USN-1941-1http://www.ubuntu.com/usn/USN-1942-1https://bugzilla.redhat.com/attachment.cgi?id=767633&action=diffhttps://bugzilla.redhat.com/show_bug.cgi?id=977356http://hkpco.kr/advisory/CVE-2013-1059.txthttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00012.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://www.openwall.com/lists/oss-security/2013/07/09/7http://www.ubuntu.com/usn/USN-1941-1http://www.ubuntu.com/usn/USN-1942-1https://bugzilla.redhat.com/attachment.cgi?id=767633&action=diffhttps://bugzilla.redhat.com/show_bug.cgi?id=977356
2013-07-08
Published