cbcvebase.
CVE-2013-2015
published 2013-04-29

CVE-2013-2015: The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems…

PriorityP415medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.38%
30.4th percentile
The ext4_orphan_del function in fs/ext4/namei.c in the Linux kernel before 3.7.3 does not properly handle orphan-list entries for non-journal filesystems, which allows physically proximate attackers to cause a denial of service (system hang) via a crafted filesystem on removable media, as demonstrated by the e2fsprogs tests/f_orphan_extents_inode/image.gz test.

Affected

193 ranges· showing 25
VendorProductVersion rangeFixed in
debianlinux< linux 3.8-1~experimental.1 (bookworm)linux 3.8-1~experimental.1 (bookworm)
debianlinux< linux 3.8-1 (bookworm)linux 3.8-1 (bookworm)
libarchivelibarchive>= 0 < 3.1.2-7ubuntu2.13.1.2-7ubuntu2.1
linuxlinux_kernel<= 3.7.2
linuxlinux_kernel<= 3.6.11
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel

CVSS provenance

nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_redhat7.5HIGH
vendor_debian4.7LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.