CVE-2013-2224
published 2013-07-04CVE-2013-2224: A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows local users to cause a denial of service (invalid free…
PriorityP421medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.35%
27.7th percentile
A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows local users to cause a denial of service (invalid free operation and system crash) or possibly gain privileges via a sendmsg system call with the IP_RETOPTS option, as demonstrated by hemlock.c. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-3552.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| redhat | enterprise_linux | — | — |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
vendor_debian5.9LOW
vendor_redhat5.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: net: IP_REPOPTS invalid free
vendor_redhat·2013-06-30·CVSS 5.9
CVE-2013-2224 [MEDIUM] kernel: net: IP_REPOPTS invalid free
kernel: net: IP_REPOPTS invalid free
A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows local users to cause a denial of service (invalid free operation and system crash) or possibly gain privileges via a sendmsg system call with the IP_RETOPTS option, as demonstrated by hemlock.c. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-3552.
Statement: This issue did not affect the version of the kernel package as shipped with Red Hat Enterprise MRG 2.
This issue affects the versions of Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6. Future kernel updates for Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6 may address this issue.
Package: kernel (Red Hat Enterprise Linux 7) -
Debian
CVE-2013-2224: linux - A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux ...
vendor_debian·2013·CVSS 5.9
CVE-2013-2224 [MEDIUM] CVE-2013-2224: linux - A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux ...
A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows local users to cause a denial of service (invalid free operation and system crash) or possibly gain privileges via a sendmsg system call with the IP_RETOPTS option, as demonstrated by hemlock.c. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-3552.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-phqq-mhr3-p67h: A certain Red Hat patch for the Linux kernel 2
ghsa_unreviewed·2022-05-14·CVSS 5.9
CVE-2013-2224 [MEDIUM] GHSA-phqq-mhr3-p67h: A certain Red Hat patch for the Linux kernel 2
A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows local users to cause a denial of service (invalid free operation and system crash) or possibly gain privileges via a sendmsg system call with the IP_RETOPTS option, as demonstrated by hemlock.c. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-3552.
No detection rules found.
No public exploits indexed.
http://rhn.redhat.com/errata/RHSA-2013-1166.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1173.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1450.htmlhttp://www.openwall.com/lists/oss-security/2013/06/30/7https://bugzilla.redhat.com/show_bug.cgi?id=979936http://rhn.redhat.com/errata/RHSA-2013-1166.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1173.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1450.htmlhttp://www.openwall.com/lists/oss-security/2013/06/30/7https://bugzilla.redhat.com/show_bug.cgi?id=979936
2013-07-04
Published