CVE-2013-2140
published 2013-09-25CVE-2013-2140: The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS…
PriorityP416low3.8CVSS 2.0
AVAACMAuSCNIPAP
EPSS
1.01%
60.1th percentile
The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only disk that supports the (1) BLKIF_OP_DISCARD (aka discard or TRIM) or (2) SCSI UNMAP feature.
Affected
224 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.10.1-1 (bookworm) | linux 3.10.1-1 (bookworm) |
| linux | linux_kernel | <= 3.10.4 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.03.8LOWAV:A/AC:M/Au:S/C:N/I:P/A:P
osv3.8LOW
vendor_ubuntu6.9MEDIUM
vendor_debian3.8LOW
vendor_redhat3.8LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-12-03·CVSS 3.2
CVE-2013-0343 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)
A flaw was discovered in the Xen subsystem of the Linux kernel when it
provides read-only access to a disk that supports TRIM or SCSI UNMAP to a
guest OS. A privileged user in the guest OS could exploit this flaw to
destroy data on the disk, even though the guest OS should not be able to
write to the disk. (CVE-2013-2140)
Kees Cook discovered flaw in the Human Interface Devic
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-12-03·CVSS 3.2
CVE-2013-0343 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)
A flaw was discovered in the Xen subsystem of the Linux kernel when it
provides read-only access to a disk that supports TRIM or SCSI UNMAP to a
guest OS. A privileged user in the guest OS could exploit this flaw to
destroy data on the disk, even though the guest OS should not be able to
write to the disk. (CVE-2013-2140)
Kees Cook discovered flaw in the Human Interfa
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-09-07·CVSS 4.0
CVE-2012-5374 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 4.0
CVE-2012-5374 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 4.0
CVE-2012-5374 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (C
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 6.9
CVE-2013-1060 [MEDIUM] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (CVE-2013-1060)
A flaw was discovered in the Xen subsystem of the Linux kernel when it
provides read-only access to a disk that supports TRIM or SCSI UNMAP to a
guest OS. A privileged user in the guest OS could exploit this flaw to
destroy data on the disk, even though the guest OS should not be able to
write to the disk. (CVE-2013-2140)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4 destination. An unprivileged local user could exploit
this flaw to
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-05·CVSS 6.9
CVE-2013-1060 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows specified to be run as root. A local could exploit this flaw to run
commands as root when using the perf tool. user could exploit this
(CVE-2013-1060)
A flaw was discovered in the Xen subsystem of the Linux kernel when it
provides read-only access to a disk that supports TRIM or SCSI UNMAP to a
guest OS. A privileged user in the guest OS could exploit this flaw to
destroy data on the disk, even though the guest OS should not be able to
write to the disk. (CVE-2013-2140)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4 destination. An unprivileged local user could exploit
thi
Red Hat
kernel: xen: blkback: insufficient permission checks for BLKIF_OP_DISCARD
vendor_redhat·2013-06-05·CVSS 3.8
CVE-2013-2140 [LOW] kernel: xen: blkback: insufficient permission checks for BLKIF_OP_DISCARD
kernel: xen: blkback: insufficient permission checks for BLKIF_OP_DISCARD
The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only disk that supports the (1) BLKIF_OP_DISCARD (aka discard or TRIM) or (2) SCSI UNMAP feature.
Statement: Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5 as it has no support for BLKIF_OP_DISCARD.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
Package: kernel-xen (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not aff
Debian
CVE-2013-2140: linux - The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the X...
vendor_debian·2013·CVSS 3.8
CVE-2013-2140 [LOW] CVE-2013-2140: linux - The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the X...
The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only disk that supports the (1) BLKIF_OP_DISCARD (aka discard or TRIM) or (2) SCSI UNMAP feature.
Scope: local
bookworm: resolved (fixed in 3.10.1-1)
bullseye: resolved (fixed in 3.10.1-1)
forky: resolved (fixed in 3.10.1-1)
sid: resolved (fixed in 3.10.1-1)
trixie: resolved (fixed in 3.10.1-1)
GHSA
GHSA-qw94-9pv3-h4jx: The dispatch_discard_io function in drivers/block/xen-blkback/blkback
ghsa_unreviewed·2022-05-17
CVE-2013-2140 [LOW] CWE-20 GHSA-qw94-9pv3-h4jx: The dispatch_discard_io function in drivers/block/xen-blkback/blkback
The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only disk that supports the (1) BLKIF_OP_DISCARD (aka discard or TRIM) or (2) SCSI UNMAP feature.
OSV
CVE-2013-2140: The dispatch_discard_io function in drivers/block/xen-blkback/blkback
osv·2013-09-25·CVSS 3.8
CVE-2013-2140 [LOW] CVE-2013-2140: The dispatch_discard_io function in drivers/block/xen-blkback/blkback
The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only disk that supports the (1) BLKIF_OP_DISCARD (aka discard or TRIM) or (2) SCSI UNMAP feature.
Kernel
xen/blkback: Check device permissions before allowing OP_DISCARD
kernel_security·2013-01-16·CVSS 3.8
CVE-2013-2140 [LOW] xen/blkback: Check device permissions before allowing OP_DISCARD
xen/blkback: Check device permissions before allowing OP_DISCARD
We need to make sure that the device is not RO or that
the request is not past the number of sectors we want to
issue the DISCARD operation for.
This fixes CVE-2013-2140.
Cc: [email protected]
Acked-by: Jan Beulich
Acked-by: Ian Campbell
[v1: Made it pr_warn instead of pr_debug]
Signed-off-by: Konrad Rzeszutek Wilk
No detection rules found.
Bugzilla
CVE-2013-2140 kernel: xen: blkback: insufficient permission checks for BLKIF_OP_DISCARD [fedora-all]
bugzilla·2013-06-05·CVSS 3.8
CVE-2013-2140 [LOW] CVE-2013-2140 kernel: xen: blkback: insufficient permission checks for BLKIF_OP_DISCARD [fedora-all]
CVE-2013-2140 kernel: xen: blkback: insufficient permission checks for BLKIF_OP_DISCARD [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Plea
Bugzilla
CVE-2013-2140 kernel: xen: blkback: insufficient permission checks for BLKIF_OP_DISCARD
bugzilla·2013-06-05·CVSS 3.8
CVE-2013-2140 [LOW] CVE-2013-2140 kernel: xen: blkback: insufficient permission checks for BLKIF_OP_DISCARD
CVE-2013-2140 kernel: xen: blkback: insufficient permission checks for BLKIF_OP_DISCARD
If a system admin provides a disk (which supports the discard aka TRIM or SCSI UNMAP) to a guest as read-only - there are no checks done.
A privileged guest user could use this flaw to destroy data on the disk to which he otherwise wouldn't have write access to.
References:
http://seclists.org/oss-sec/2013/q2/488
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of the kernel-xen package as shipped with Red Hat Enterprise Linux 5 as it has no support for BLKIF_OP_DISCARD.
This issue did not affect Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
---
Created kernel tracking bugs for this issue
Affects: fedora-all [bug 971148]
---
For future reference:
ht
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=604c499cbbcc3d5fe5fb8d53306aa0fae1990109http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-2140.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.5http://www.openwall.com/lists/oss-security/2013/06/05/21http://www.ubuntu.com/usn/USN-1938-1http://www.ubuntu.com/usn/USN-1943-1http://www.ubuntu.com/usn/USN-1944-1http://www.ubuntu.com/usn/USN-1945-1http://www.ubuntu.com/usn/USN-1946-1http://www.ubuntu.com/usn/USN-1947-1http://www.ubuntu.com/usn/USN-2038-1http://www.ubuntu.com/usn/USN-2039-1https://bugzilla.redhat.com/show_bug.cgi?id=971146https://github.com/torvalds/linux/commit/604c499cbbcc3d5fe5fb8d53306aa0fae1990109http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=604c499cbbcc3d5fe5fb8d53306aa0fae1990109http://people.canonical.com/~ubuntu-security/cve/2013/CVE-2013-2140.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.5http://www.openwall.com/lists/oss-security/2013/06/05/21http://www.ubuntu.com/usn/USN-1938-1http://www.ubuntu.com/usn/USN-1943-1http://www.ubuntu.com/usn/USN-1944-1http://www.ubuntu.com/usn/USN-1945-1http://www.ubuntu.com/usn/USN-1946-1http://www.ubuntu.com/usn/USN-1947-1http://www.ubuntu.com/usn/USN-2038-1http://www.ubuntu.com/usn/USN-2039-1https://bugzilla.redhat.com/show_bug.cgi?id=971146https://github.com/torvalds/linux/commit/604c499cbbcc3d5fe5fb8d53306aa0fae1990109
2013-09-25
Published