CVE-2013-2147Kernel vulnerability

CWE-39920 documents9 sources
Severity
2.1LOWNVD
EPSS
0.1%
top 77.15%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 7
Latest updateMay 14

Description

The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via (1) a crafted IDAGETPCIINFO command for a /dev/ida device, related to the ida_locked_ioctl function in drivers/block/cpqarray.c or (2) a crafted CCISS_PASSTHRU32 command for a /dev/cciss device, related to the cciss_ioctl32_passthru function in dri

CVSS vector

AV:L/AC:L/C:P/I:N/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages3 packages

🔴Vulnerability Details

5
GHSA
GHSA-c99v-g47p-v8gp: The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 32022-05-14
Kernel
cpqarray: fix info leak in ida_locked_ioctl()2013-09-24
Kernel
cciss: fix info leak in cciss_ioctl32_passthru()2013-09-24
OSV
CVE-2013-2147: The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 32013-06-07
CVEList
CVE-2013-2147: The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 32013-06-07

📋Vendor Advisories

12
Ubuntu
Linux kernel (OMAP4) vulnerabilities2013-12-07
Ubuntu
Linux kernel vulnerabilities2013-11-08
Ubuntu
Linux kernel (OMAP4) vulnerabilities2013-11-08
Ubuntu
Linux kernel vulnerabilities2013-11-08
Ubuntu
Linux kernel vulnerabilities2013-11-08

💬Community

2
Bugzilla
CVE-2013-2147 Kernel: cpqarray/cciss: information leak via ioctl2013-06-06
Bugzilla
CVE-2013-2147 Kernel: cpqarray/cciss: information leak via ioctl [fedora-all]2013-06-06
CVE-2013-2147 — Linux Kernel vulnerability | cvebase