CVE-2013-1767
published 2013-02-28CVE-2013-1767: Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a…
PriorityP421medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.50%
40.1th percentile
Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.
Affected
155 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.41-1 (bookworm) | linux 3.2.41-1 (bookworm) |
| linux | linux_kernel | <= 3.7.9 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
vendor_ubuntu6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-323p-r9jj-62gh: Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem
ghsa_unreviewed·2022-05-17
CVE-2013-1767 [MEDIUM] GHSA-323p-r9jj-62gh: Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem
Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.
OSV
CVE-2013-1767: Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem
osv·2013-02-28·CVSS 6.2
CVE-2013-1767 [MEDIUM] CVE-2013-1767: Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem
Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2013-04-09·CVSS 1.9
CVE-2012-6537 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered several errors in the Linux kernel's xfrm_user
implementation. A local attacker could exploit these flaws to examine parts
of kernel memory. (CVE-2012-6537)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible t
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 3.6
CVE-2013-0914 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2013-1792)
Mathias
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 6.2
CVE-2013-0228 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-0228)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem.
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 6.2
CVE-2013-0228 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-0228)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesy
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 3.6
CVE-2013-0914 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2013-1792)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 1.9
CVE-2012-6537 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathias Krause discovered several errors in the Linux kernel's xfrm_user
implementation. A local attacker could exploit these flaws to examine parts
of kernel memory. (CVE-2012-6537)
Mathias Krause discovered information leak in the Linux kernel's compat
ioctl interface. A local user could exploit the flaw to examine parts of
kernel stack memory (CVE-2012-6539)
Mathias Krause discovered an information leak in the Linux kernel's
getsockopt for IP_VS_SO_GET_TIMEOUT. A local user could exploit this flaw
to examine parts of kernel stack memory. (CVE-2012-6540)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by p
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-08·CVSS 6.2
CVE-2013-0228 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-0228)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local
Ubuntu
Linux kernel (Oneiric backport) vulnerabilities
vendor_ubuntu·2013-04-04·CVSS 3.6
CVE-2013-0914 [LOW] Linux kernel (Oneiric backport) vulnerabilities
Title: Linux kernel (Oneiric backport) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to bypass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
bypass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discovered in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-04-02·CVSS 3.6
CVE-2013-0914 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2013-1792)
Instruct
Red Hat
Kernel: tmpfs: fix use-after-free of mempolicy object
vendor_redhat·2013-02-24·CVSS 6.2
CVE-2013-1767 [MEDIUM] CWE-416 Kernel: tmpfs: fix use-after-free of mempolicy object
Kernel: tmpfs: fix use-after-free of mempolicy object
Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2013-1767: linux - Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in t...
vendor_debian·2013·CVSS 6.2
CVE-2013-1767 [MEDIUM] CVE-2013-1767: linux - Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in t...
Use-after-free vulnerability in the shmem_remount_fs function in mm/shmem.c in the Linux kernel before 3.7.10 allows local users to gain privileges or cause a denial of service (system crash) by remounting a tmpfs filesystem without specifying a required mpol (aka mempolicy) mount option.
Scope: local
bookworm: resolved (fixed in 3.2.41-1)
bullseye: resolved (fixed in 3.2.41-1)
forky: resolved (fixed in 3.2.41-1)
sid: resolved (fixed in 3.2.41-1)
trixie: resolved (fixed in 3.2.41-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-1767 Kernel: tmpfs: fix use-after-free of mempolicy object [fedora-all]
bugzilla·2013-02-26·CVSS 6.2
CVE-2013-1767 [MEDIUM] CVE-2013-1767 Kernel: tmpfs: fix use-after-free of mempolicy object [fedora-all]
CVE-2013-1767 Kernel: tmpfs: fix use-after-free of mempolicy object [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
Bugzilla
CVE-2013-1767 Kernel: tmpfs: fix use-after-free of mempolicy object
bugzilla·2013-02-26·CVSS 6.2
CVE-2013-1767 [MEDIUM] CVE-2013-1767 Kernel: tmpfs: fix use-after-free of mempolicy object
CVE-2013-1767 Kernel: tmpfs: fix use-after-free of mempolicy object
Linux kernel built with support to `tmpfs' is vulnerable to a use-after-free flaw, which happens while remounting tmpfs, which was mounted with mpol=M option initially, but the same is missing in the remount request.
A privileged local user could use this flaw to crash the system or, potentially, further escalate their privileges.
Upstream fix:
-> https://git.kernel.org/linus/5f00110f7273f9ff04ac69a5f85bb535a4fd0987
References:
1] http://www.openwall.com/lists/oss-security/2013/02/25/14
Discussion:
Statement:
This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat E
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5f00110f7273f9ff04ac69a5f85bb535a4fd0987http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0744.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0882.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0928.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.10http://www.mandriva.com/security/advisories?name=MDVSA-2013:176http://www.openwall.com/lists/oss-security/2013/02/25/23http://www.ubuntu.com/usn/USN-1787-1http://www.ubuntu.com/usn/USN-1788-1http://www.ubuntu.com/usn/USN-1792-1http://www.ubuntu.com/usn/USN-1793-1http://www.ubuntu.com/usn/USN-1794-1http://www.ubuntu.com/usn/USN-1795-1http://www.ubuntu.com/usn/USN-1796-1http://www.ubuntu.com/usn/USN-1797-1http://www.ubuntu.com/usn/USN-1798-1https://bugzilla.redhat.com/show_bug.cgi?id=915592https://github.com/torvalds/linux/commit/5f00110f7273f9ff04ac69a5f85bb535a4fd0987http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5f00110f7273f9ff04ac69a5f85bb535a4fd0987http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0744.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0882.htmlhttp://rhn.redhat.com/errata/RHSA-2013-0928.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.10http://www.mandriva.com/security/advisories?name=MDVSA-2013:176http://www.openwall.com/lists/oss-security/2013/02/25/23http://www.ubuntu.com/usn/USN-1787-1http://www.ubuntu.com/usn/USN-1788-1http://www.ubuntu.com/usn/USN-1792-1http://www.ubuntu.com/usn/USN-1793-1http://www.ubuntu.com/usn/USN-1794-1http://www.ubuntu.com/usn/USN-1795-1http://www.ubuntu.com/usn/USN-1796-1http://www.ubuntu.com/usn/USN-1797-1http://www.ubuntu.com/usn/USN-1798-1https://bugzilla.redhat.com/show_bug.cgi?id=915592https://github.com/torvalds/linux/commit/5f00110f7273f9ff04ac69a5f85bb535a4fd0987
2013-02-28
Published