CVE-2013-2058
published 2013-11-04CVE-2013-2058: The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a certain non-streaming option, which allows…
PriorityP415medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.45%
37.3th percentile
The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a certain non-streaming option, which allows local users to cause a denial of service (system crash) by sending a large amount of network traffic through a USB/Ethernet adapter.
Affected
201 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.8-1 (bookworm) | linux 3.8-1 (bookworm) |
| linux | linux_kernel | <= 3.7.3 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
ghsa4.0MEDIUM
osv4.7MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2wg2-3f8r-rjg8: The host_start function in drivers/usb/chipidea/host
ghsa_unreviewed·2022-05-17
CVE-2013-2058 [MEDIUM] CWE-119 GHSA-2wg2-3f8r-rjg8: The host_start function in drivers/usb/chipidea/host
The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a certain non-streaming option, which allows local users to cause a denial of service (system crash) by sending a large amount of network traffic through a USB/Ethernet adapter.
GHSA
Jenkins allows attackers to execute arbitrary jobs
ghsa·2022-05-17·CVSS 4.0
CVE-2014-2058 [MEDIUM] Jenkins allows attackers to execute arbitrary jobs
Jenkins allows attackers to execute arbitrary jobs
BuildTrigger in Jenkins before 1.551 and LTS before 1.532.2 allows remote authenticated users to bypass access restrictions and execute arbitrary jobs by configuring a job to trigger another job. NOTE: this vulnerability exists because of an incomplete fix for CVE-2013-7330.
OSV
CVE-2013-2058: The host_start function in drivers/usb/chipidea/host
osv·2013-11-04·CVSS 4.7
CVE-2013-2058 [MEDIUM] CVE-2013-2058: The host_start function in drivers/usb/chipidea/host
The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a certain non-streaming option, which allows local users to cause a denial of service (system crash) by sending a large amount of network traffic through a USB/Ethernet adapter.
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2013-02-22·CVSS 6.9
CVE-2013-0871 [MEDIUM] Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
(CVE-2013-0871)
A flaw was discovered in the Edgeort USB serial converter driver when the
device is disconnected while it is in use. A local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2013-1774)
A flaw was discovered in the ChipIdea Highspeed Dual Role and ChipIdea host
controller drivers in the Linux kernel. A local user could use this flaw to
cause a denial of service (system crash). (CVE-2013-2058)
Instructions: Afte
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2013-02-22·CVSS 6.9
CVE-2013-0871 [MEDIUM] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
(CVE-2013-0871)
A flaw was discovered in the Edgeort USB serial converter driver when the
device is disconnected while it is in use. A local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2013-1774)
A flaw was discovered in the ChipIdea Highspeed Dual Role and ChipIdea host
controller drivers in the Linux kernel. A local user could use this flaw to
cause a denial of service (system crash). (CVE-2013-2058)
Instructions: After a stan
Ubuntu
Linux kernel (Quantal HWE) vulnerability
vendor_ubuntu·2013-02-22·CVSS 6.9
CVE-2013-0871 [MEDIUM] Linux kernel (Quantal HWE) vulnerability
Title: Linux kernel (Quantal HWE) vulnerability
Summary: The system could be made to run programs as an administrator.
Suleiman Souhlal, Salman Qazi, Aaron Durbin and Michael Davidson discovered
a race condition in the Linux kernel's ptrace syscall. An unprivileged
local attacker could exploit this flaw to run programs as an administrator.
(CVE-2013-0871)
A flaw was discovered in the Edgeort USB serial converter driver when the
device is disconnected while it is in use. A local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2013-1774)
A flaw was discovered in the ChipIdea Highspeed Dual Role and ChipIdea host
controller drivers in the Linux kernel. A local user could use this flaw to
cause a denial of service (system crash). (CVE-2013-2058)
Instructions
Debian
CVE-2013-2058: linux - The host_start function in drivers/usb/chipidea/host.c in the Linux kernel befor...
vendor_debian·2013·CVSS 4.7
CVE-2013-2058 [MEDIUM] CVE-2013-2058: linux - The host_start function in drivers/usb/chipidea/host.c in the Linux kernel befor...
The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a certain non-streaming option, which allows local users to cause a denial of service (system crash) by sending a large amount of network traffic through a USB/Ethernet adapter.
Scope: local
bookworm: resolved (fixed in 3.8-1)
bullseye: resolved (fixed in 3.8-1)
forky: resolved (fixed in 3.8-1)
sid: resolved (fixed in 3.8-1)
trixie: resolved (fixed in 3.8-1)
Red Hat
Kernel: usb: chipidea: Allow disabling streaming not just in udc mode
vendor_redhat·2012-12-22·CVSS 4.7
CVE-2013-2058 [MEDIUM] Kernel: usb: chipidea: Allow disabling streaming not just in udc mode
Kernel: usb: chipidea: Allow disabling streaming not just in udc mode
The host_start function in drivers/usb/chipidea/host.c in the Linux kernel before 3.7.4 does not properly support a certain non-streaming option, which allows local users to cause a denial of service (system crash) by sending a large amount of network traffic through a USB/Ethernet adapter.
Statement: This issue does not affect the versions of Linux kernel as shipped with
Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6.
This issue affects the version of the kernel package as shipped with
Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise MRG 2
may address this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=929473ea05db455ad88cdc081f2adc556b8dc48fhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.4http://www.openwall.com/lists/oss-security/2013/05/05/2https://bugzilla.redhat.com/show_bug.cgi?id=959210https://github.com/torvalds/linux/commit/929473ea05db455ad88cdc081f2adc556b8dc48fhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=929473ea05db455ad88cdc081f2adc556b8dc48fhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.4http://www.openwall.com/lists/oss-security/2013/05/05/2https://bugzilla.redhat.com/show_bug.cgi?id=959210https://github.com/torvalds/linux/commit/929473ea05db455ad88cdc081f2adc556b8dc48f
2013-11-04
Published