CVE-2013-2188
published 2013-07-16CVE-2013-2188: A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does…
PriorityP414medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.32%
24.3th percentile
A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle failure to obtain write permissions, which allows local users to cause a denial of service (system crash) by leveraging access to a filesystem that is mounted read-only.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
vendor_debian4.7LOW
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: fs: filp leak on ro filesystem
vendor_redhat·2013-06-17·CVSS 4.7
CVE-2013-2188 [MEDIUM] kernel: fs: filp leak on ro filesystem
kernel: fs: filp leak on ro filesystem
A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle failure to obtain write permissions, which allows local users to cause a denial of service (system crash) by leveraging access to a filesystem that is mounted read-only.
Statement: This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux MRG 2.
This issue was addressed in Red Hat Enterprise Linux 6 via RHSA-2013:0911 (https://rhn.redhat.com/errata/RHSA-2013-0911.html).
Upstream is not affected.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affec
Debian
CVE-2013-2188: linux - A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel...
vendor_debian·2013·CVSS 4.7
CVE-2013-2188 [MEDIUM] CVE-2013-2188: linux - A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel...
A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle failure to obtain write permissions, which allows local users to cause a denial of service (system crash) by leveraging access to a filesystem that is mounted read-only.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-p5g4-c6vw-x6q8: A certain Red Hat patch to the do_filp_open function in fs/namei
ghsa_unreviewed·2022-05-14
CVE-2013-2188 [MEDIUM] GHSA-p5g4-c6vw-x6q8: A certain Red Hat patch to the do_filp_open function in fs/namei
A certain Red Hat patch to the do_filp_open function in fs/namei.c in the kernel package before 2.6.32-358.11.1.el6 on Red Hat Enterprise Linux (RHEL) 6 does not properly handle failure to obtain write permissions, which allows local users to cause a denial of service (system crash) by leveraging access to a filesystem that is mounted read-only.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6167 Mozilla: browser document.cookie DoS vulnerability
bugzilla·2014-02-18·CVSS 6.8
CVE-2013-6167 [MEDIUM] CVE-2013-6167 Mozilla: browser document.cookie DoS vulnerability
CVE-2013-6167 Mozilla: browser document.cookie DoS vulnerability
Common Vulnerabilities and Exposures assigned an identifier CVE-2013-6167 to
the following vulnerability:
Name: CVE-2013-6167
URL: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-6167
Assigned: 20131016
Reference: http://www.openwall.com/lists/oss-security/2013/04/03/10
Reference: http://seclists.org/oss-sec/2013/q4/117
Reference: http://seclists.org/oss-sec/2013/q4/121
Reference: http://redmine.lighttpd.net/issues/2188
Reference: https://bugzilla.mozilla.org/show_bug.cgi?id=858215
Mozilla Firefox through 27 sends HTTP Cookie headers without first
validating that they have the required character-set restrictions,
which allows remote attackers to conduct the equivalent of a
persistent Logout CSRF attack via a crafted
Bugzilla
CVE-2013-2188 kernel: fs: filp leak on ro filesystem
bugzilla·2013-06-18·CVSS 4.7
CVE-2013-2188 [MEDIUM] CVE-2013-2188 kernel: fs: filp leak on ro filesystem
CVE-2013-2188 kernel: fs: filp leak on ro filesystem
A flaw was found in the way do_filp_open() function in the Linux kernel handled cleanup in case write access to a mount was denied. A local unprivileged user with acces to a read-only mount could use this flaw to crash the system.
This issue affected Red Hat Enterprise Linux 6 only. Upstream is not affected.
Acknowledgements:
This issue was discovered by Mateusz Guzik of Red Hat.
Discussion:
Statement:
This issue did not affect the Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux MRG 2.
This issue was addressed in Red Hat Enterprise Linux 6 via RHSA-2013:0911 (https://rhn.redhat.com/errata/RHSA-2013-0911.html).
Upstream is not affected.
2013-07-16
Published