CVE-2013-1772
published 2013-02-28CVE-2013-1772: The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows…
PriorityP414medium4CVSS 2.0
AVLACHAuNCNINAC
EPSS
0.38%
30.7th percentile
The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.
Affected
134 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.2.39-1 (bookworm) | linux 3.2.39-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:L/AC:H/Au:N/C:N/I:N/A:C
osv4.0MEDIUM
vendor_ubuntu6.2MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-03-26·CVSS 6.2
CVE-2013-0228 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-0228)
A flaw was reported in the permission checks done by the Linux kernel for
/dev/cpu/*/msr. A local root user with all capabilities dropped could
exploit this flaw to execute code with full root capabilities.
(CVE-2013-0268)
A flaw was discovered in the Linux kernel's vhost driver used to accelerate
guest networking in KVM based virtual machines. A privileged guest user
could exploit this flaw to crash the host s
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-03-18·CVSS 4.9
CVE-2013-0190 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andrew Cooper of Citrix reported a Xen stack corruption in the Linux
kernel. An unprivileged user in a 32bit PVOPS guest can cause the guest
kernel to crash, or operate erroneously. (CVE-2013-0190)
A failure to validate input was discovered in the Linux kernel's Xen
netback (network backend) driver. A user in a guest OS may exploit this
flaw to cause a denial of service to the guest OS and other guest domains.
(CVE-2013-0216)
A memory leak was discovered in the Linux kernel's Xen netback (network
backend) driver. A user in a guest OS could trigger this flaw to cause a
denial of service on the system. (CVE-2013-0217)
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Red Hat
kernel: call_console_drivers() function log prefix stripping DoS
vendor_redhat·2013-02-22·CVSS 4.0
CVE-2013-1772 [MEDIUM] kernel: call_console_drivers() function log prefix stripping DoS
kernel: call_console_drivers() function log prefix stripping DoS
The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.
Statement: This issue did not affect the versions of kernel package as shipped with Red Hat Enterprise Linux 5 and 6. Future kernel updates for Red Hat Enterprise MRG 2 may address this flaw.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2013-1772: linux - The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33...
vendor_debian·2013·CVSS 4.0
CVE-2013-1772 [MEDIUM] CVE-2013-1772: linux - The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33...
The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.
Scope: local
bookworm: resolved (fixed in 3.2.39-1)
bullseye: resolved (fixed in 3.2.39-1)
forky: resolved (fixed in 3.2.39-1)
sid: resolved (fixed in 3.2.39-1)
trixie: resolved (fixed in 3.2.39-1)
GHSA
GHSA-58hg-m3wr-hj5r: The log_prefix function in kernel/printk
ghsa_unreviewed·2022-05-17
CVE-2013-1772 [MEDIUM] CWE-119 GHSA-58hg-m3wr-hj5r: The log_prefix function in kernel/printk
The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.
OSV
CVE-2013-1772: The log_prefix function in kernel/printk
osv·2013-02-28·CVSS 4.0
CVE-2013-1772 [MEDIUM] CVE-2013-1772: The log_prefix function in kernel/printk
The log_prefix function in kernel/printk.c in the Linux kernel 3.x before 3.4.33 does not properly remove a prefix string from a syslog header, which allows local users to cause a denial of service (buffer overflow and system crash) by leveraging /dev/kmsg write access and triggering a call_console_drivers function call.
No detection rules found.
No public exploits indexed.
http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.33http://www.openwall.com/lists/oss-security/2013/02/26/9https://bugzilla.redhat.com/show_bug.cgi?id=916075https://github.com/torvalds/linux/commit/ce0030c00f95cf9110d9cdcd41e901e1fb814417http://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.4.33http://www.openwall.com/lists/oss-security/2013/02/26/9https://bugzilla.redhat.com/show_bug.cgi?id=916075https://github.com/torvalds/linux/commit/ce0030c00f95cf9110d9cdcd41e901e1fb814417
2013-02-28
Published