CVE-2013-2147
published 2013-06-07CVE-2013-2147: The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.42%
34.5th percentile
The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via (1) a crafted IDAGETPCIINFO command for a /dev/ida device, related to the ida_locked_ioctl function in drivers/block/cpqarray.c or (2) a crafted CCISS_PASSTHRU32 command for a /dev/cciss device, related to the cciss_ioctl32_passthru function in drivers/block/cciss.c.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.11.5-1 (bookworm) | linux 3.11.5-1 (bookworm) |
| linux | linux_kernel | <= 3.9.4 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.11.5-1 | 3.11.5-1 |
| linux | linux_kernel | >= 0 < 3.11.5-1 | 3.11.5-1 |
| linux | linux_kernel | >= 0 < 3.11.5-1 | 3.11.5-1 |
| linux | linux_kernel | >= 0 < 3.11.5-1 | 3.11.5-1 |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_ubuntu4.0MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-c99v-g47p-v8gp: The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3
ghsa_unreviewed·2022-05-14
CVE-2013-2147 [LOW] GHSA-c99v-g47p-v8gp: The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3
The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via (1) a crafted IDAGETPCIINFO command for a /dev/ida device, related to the ida_locked_ioctl function in drivers/block/cpqarray.c or (2) a crafted CCISS_PASSTHRU32 command for a /dev/cciss device, related to the cciss_ioctl32_passthru function in drivers/block/cciss.c.
Kernel
cpqarray: fix info leak in ida_locked_ioctl()
kernel_security·2013-09-24·CVSS 2.1
CVE-2013-2147 [LOW] cpqarray: fix info leak in ida_locked_ioctl()
cpqarray: fix info leak in ida_locked_ioctl()
The pciinfo struct has a two byte hole after ->dev_fn so stack
information could be leaked to the user.
This was assigned CVE-2013-2147.
Signed-off-by: Dan Carpenter
Acked-by: Mike Miller
Signed-off-by: Andrew Morton
Signed-off-by: Linus Torvalds
Kernel
cciss: fix info leak in cciss_ioctl32_passthru()
kernel_security·2013-09-24·CVSS 2.1
CVE-2013-2147 [LOW] cciss: fix info leak in cciss_ioctl32_passthru()
cciss: fix info leak in cciss_ioctl32_passthru()
The arg64 struct has a hole after ->buf_size which isn't cleared. Or if
any of the calls to copy_from_user() fail then that would cause an
information leak as well.
This was assigned CVE-2013-2147.
Signed-off-by: Dan Carpenter
Acked-by: Mike Miller
Signed-off-by: Andrew Morton
Signed-off-by: Linus Torvalds
OSV
CVE-2013-2147: The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3
osv·2013-06-07·CVSS 2.1
CVE-2013-2147 [LOW] CVE-2013-2147: The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3
The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via (1) a crafted IDAGETPCIINFO command for a /dev/ida device, related to the ida_locked_ioctl function in drivers/block/cpqarray.c or (2) a crafted CCISS_PASSTHRU32 command for a /dev/cciss device, related to the cciss_ioctl32_passthru function in drivers/block/cciss.c.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-12-07·CVSS 3.2
CVE-2013-0343 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-2147)
Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit th
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-11-08·CVSS 3.2
CVE-2013-0343 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-2147)
Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
le
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-11-08·CVSS 4.0
CVE-2012-5374 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive inf
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-11-08·CVSS 2.1
CVE-2013-2147 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-2147)
Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
leverage this flaw to cause a denial of service via a specially crafted
device. (CVE-2013-2889)
Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,
CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially
proximate attacker can leve
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-11-08·CVSS 4.0
CVE-2012-5374 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-11-08·CVSS 3.2
CVE-2013-0343 [LOW] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the handling of ICMPv6 Router
Advertisement (RA) messages in the Linux kernel's IPv6 network stack. A
remote attacker could exploit this flaw to cause a denial of service
(excessive retries and address-generation outage), and consequently obtain
sensitive information. (CVE-2013-0343)
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-2147)
Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate atta
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2013-11-08·CVSS 2.1
CVE-2013-2147 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
(CVE-2013-2147)
Kees Cook discovered flaw in the Human Interface Device (HID) subsystem
when CONFIG_HID_ZEROPLUS is enabled. A physically proximate attacker could
leverage this flaw to cause a denial of service via a specially crafted
device. (CVE-2013-2889)
Kees Cook discovered another flaw in the Human Interface Device (HID)
subsystem of the Linux kernel when any of CONFIG_LOGITECH_FF,
CONFIG_LOGIG940_FF, or CONFIG_LOGIWHEELS_FF are enabled. A physcially
proximate attacker ca
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2013-10-22
CVE-2013-2147 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to expose sensitive information to a local user.
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless you
manual
Ubuntu
Linux kernel (Quantal HWE) vulnerability
vendor_ubuntu·2013-10-22
CVE-2013-2147 Linux kernel (Quantal HWE) vulnerability
Title: Linux kernel (Quantal HWE) vulnerability
Summary: The system could be made to expose sensitive information to a local user.
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unl
Ubuntu
Linux kernel (OMAP4) vulnerability
vendor_ubuntu·2013-10-22
CVE-2013-2147 Linux kernel (OMAP4) vulnerability
Title: Linux kernel (OMAP4) vulnerability
Summary: The system could be made to expose sensitive information to a local user.
Dan Carpenter discovered an information leak in the HP Smart Array and
Compaq SMART2 disk-array driver in the Linux kernel. A local user could
exploit this flaw to obtain sensitive information from kernel memory.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which work with the new kernel version. Unless yo
Red Hat
Kernel: cpqarray/cciss: information leak via ioctl
vendor_redhat·2013-06-03·CVSS 2.1
CVE-2013-2147 [LOW] Kernel: cpqarray/cciss: information leak via ioctl
Kernel: cpqarray/cciss: information leak via ioctl
The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via (1) a crafted IDAGETPCIINFO command for a /dev/ida device, related to the ida_locked_ioctl function in drivers/block/cpqarray.c or (2) a crafted CCISS_PASSTHRU32 command for a /dev/cciss device, related to the cciss_ioctl32_passthru function in drivers/block/cciss.c.
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Debian
CVE-2013-2147: linux - The HP Smart Array controller disk-array driver and Compaq SMART2 controller dis...
vendor_debian·2013·CVSS 2.1
CVE-2013-2147 [LOW] CVE-2013-2147: linux - The HP Smart Array controller disk-array driver and Compaq SMART2 controller dis...
The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via (1) a crafted IDAGETPCIINFO command for a /dev/ida device, related to the ida_locked_ioctl function in drivers/block/cpqarray.c or (2) a crafted CCISS_PASSTHRU32 command for a /dev/cciss device, related to the cciss_ioctl32_passthru function in drivers/block/cciss.c.
Scope: local
bookworm: resolved (fixed in 3.11.5-1)
bullseye: resolved (fixed in 3.11.5-1)
forky: resolved (fixed in 3.11.5-1)
sid: resolved (fixed in 3.11.5-1)
trixie: resolved (fixed in 3.11.5-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2147 Kernel: cpqarray/cciss: information leak via ioctl
bugzilla·2013-06-06·CVSS 2.1
CVE-2013-2147 [LOW] CVE-2013-2147 Kernel: cpqarray/cciss: information leak via ioctl
CVE-2013-2147 Kernel: cpqarray/cciss: information leak via ioctl
Linux kernel built with the Compaq SMART2(CONFIG_BLK_CPQ_DA) & Compaq
Smart Array 5xxx(CONFIG_BLK_CPQ_CISS_DA) support is vulnerable to an
information leakage flaw. This could occur while doing ioctl(2) calls
on block devices - /dev/ida/* & /dev/cciss/* - with command `IDAGETPCIINFO'
or `CCISS_PASSTHRU32'.
A user/program able to access above devices could use this flaw to leak kernel
memory bytes.
Upstream fixes:
-> https://lkml.org/lkml/2013/6/3/131
-> https://lkml.org/lkml/2013/6/3/127
Discussion:
Statement:
This issue does not affect the version of Linux kernel as shipped with
Red Hat Enterprise Linux 6.
This issue affects the version of the kernel packages as shipped with
Red Hat Enterprise Linux 5 and Red Hat Ente
Bugzilla
CVE-2013-2147 Kernel: cpqarray/cciss: information leak via ioctl [fedora-all]
bugzilla·2013-06-06·CVSS 2.1
CVE-2013-2147 [LOW] CVE-2013-2147 Kernel: cpqarray/cciss: information leak via ioctl [fedora-all]
CVE-2013-2147 Kernel: cpqarray/cciss: information leak via ioctl [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue aff
http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://lkml.org/lkml/2013/6/3/127http://lkml.org/lkml/2013/6/3/131http://rhn.redhat.com/errata/RHSA-2013-1166.htmlhttp://www.openwall.com/lists/oss-security/2013/06/05/25http://www.ubuntu.com/usn/USN-1994-1http://www.ubuntu.com/usn/USN-1996-1http://www.ubuntu.com/usn/USN-1997-1http://www.ubuntu.com/usn/USN-1999-1http://www.ubuntu.com/usn/USN-2015-1http://www.ubuntu.com/usn/USN-2016-1http://www.ubuntu.com/usn/USN-2017-1http://www.ubuntu.com/usn/USN-2020-1http://www.ubuntu.com/usn/USN-2023-1http://www.ubuntu.com/usn/USN-2050-1https://bugzilla.redhat.com/show_bug.cgi?id=971242http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://lkml.org/lkml/2013/6/3/127http://lkml.org/lkml/2013/6/3/131http://rhn.redhat.com/errata/RHSA-2013-1166.htmlhttp://www.openwall.com/lists/oss-security/2013/06/05/25http://www.ubuntu.com/usn/USN-1994-1http://www.ubuntu.com/usn/USN-1996-1http://www.ubuntu.com/usn/USN-1997-1http://www.ubuntu.com/usn/USN-1999-1http://www.ubuntu.com/usn/USN-2015-1http://www.ubuntu.com/usn/USN-2016-1http://www.ubuntu.com/usn/USN-2017-1http://www.ubuntu.com/usn/USN-2020-1http://www.ubuntu.com/usn/USN-2023-1http://www.ubuntu.com/usn/USN-2050-1https://bugzilla.redhat.com/show_bug.cgi?id=971242
2013-06-07
Published