CVE-2013-2232
published 2013-07-04CVE-2013-2232: The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel before 3.10 allows local users to cause a denial of service (system crash) by using…
PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.56%
43.6th percentile
The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel before 3.10 allows local users to cause a denial of service (system crash) by using an AF_INET6 socket for a connection to an IPv4 interface.
Affected
208 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.10.1-1 (bookworm) | linux 3.10.1-1 (bookworm) |
| linux | linux_kernel | <= 3.9.9 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-09-07·CVSS 4.0
CVE-2012-5374 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 4.0
CVE-2012-5374 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 4.0
CVE-2012-5374 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (C
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 6.9
CVE-2013-1060 [MEDIUM] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (CVE-2013-1060)
A flaw was discovered in the Xen subsystem of the Linux kernel when it
provides read-only access to a disk that supports TRIM or SCSI UNMAP to a
guest OS. A privileged user in the guest OS could exploit this flaw to
destroy data on the disk, even though the guest OS should not be able to
write to the disk. (CVE-2013-2140)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4 destination. An unprivileged local user could exploit
this flaw to
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (CVE-2013-1060)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (CVE-2013-1060)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-05·CVSS 6.9
CVE-2013-1060 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows specified to be run as root. A local could exploit this flaw to run
commands as root when using the perf tool. user could exploit this
(CVE-2013-1060)
A flaw was discovered in the Xen subsystem of the Linux kernel when it
provides read-only access to a disk that supports TRIM or SCSI UNMAP to a
guest OS. A privileged user in the guest OS could exploit this flaw to
destroy data on the disk, even though the guest OS should not be able to
write to the disk. (CVE-2013-2140)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4 destination. An unprivileged local user could exploit
thi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-07-29·CVSS 2.1
CVE-2013-2164 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4 destination. An unprivileged local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2013-2232)
An information leak was discovered in the IPSec key_socket implementation
in the Linux kernel. An local user could exploit this flaw to examine
potentially sensitive information in kernel memory. (CVE-2013-2234)
An information leak was discovered in the Linux
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2013-07-29·CVSS 2.1
CVE-2013-2164 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4 destination. An unprivileged local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2013-2232)
An information leak was discovered in the IPSec key_socket implementation
in the Linux kernel. An local user could exploit this flaw to examine
potentially sensitive information in kernel memory. (CVE-2013-2234)
An information leak was discovered in the
Red Hat
Kernel: ipv6: using ipv4 vs ipv6 structure during routing lookup in sendmsg
vendor_redhat·2013-03-29·CVSS 4.9
CVE-2013-2232 [MEDIUM] Kernel: ipv6: using ipv4 vs ipv6 structure during routing lookup in sendmsg
Kernel: ipv6: using ipv4 vs ipv6 structure during routing lookup in sendmsg
The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel before 3.10 allows local users to cause a denial of service (system crash) by using an AF_INET6 socket for a connection to an IPv4 interface.
Statement: This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2 may address this issue.
Debian
CVE-2013-2232: linux - The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel befor...
vendor_debian·2013·CVSS 4.9
CVE-2013-2232 [MEDIUM] CVE-2013-2232: linux - The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel befor...
The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel before 3.10 allows local users to cause a denial of service (system crash) by using an AF_INET6 socket for a connection to an IPv4 interface.
Scope: local
bookworm: resolved (fixed in 3.10.1-1)
bullseye: resolved (fixed in 3.10.1-1)
forky: resolved (fixed in 3.10.1-1)
sid: resolved (fixed in 3.10.1-1)
trixie: resolved (fixed in 3.10.1-1)
GHSA
GHSA-rrc6-3p6m-fxc6: The ip6_sk_dst_check function in net/ipv6/ip6_output
ghsa_unreviewed·2022-05-17
CVE-2013-2232 [MEDIUM] CWE-20 GHSA-rrc6-3p6m-fxc6: The ip6_sk_dst_check function in net/ipv6/ip6_output
The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel before 3.10 allows local users to cause a denial of service (system crash) by using an AF_INET6 socket for a connection to an IPv4 interface.
OSV
CVE-2013-2232: The ip6_sk_dst_check function in net/ipv6/ip6_output
osv·2013-07-04·CVSS 4.9
CVE-2013-2232 [MEDIUM] CVE-2013-2232: The ip6_sk_dst_check function in net/ipv6/ip6_output
The ip6_sk_dst_check function in net/ipv6/ip6_output.c in the Linux kernel before 3.10 allows local users to cause a denial of service (system crash) by using an AF_INET6 socket for a connection to an IPv4 interface.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2232 Kernel: ipv6: using ipv4 vs ipv6 structure during routing lookup in sendmsg
bugzilla·2013-07-05·CVSS 4.9
CVE-2013-2232 [MEDIUM] CVE-2013-2232 Kernel: ipv6: using ipv4 vs ipv6 structure during routing lookup in sendmsg
CVE-2013-2232 Kernel: ipv6: using ipv4 vs ipv6 structure during routing lookup in sendmsg
Linux kernel built with the IPv6 networking support is vulnerable to an
invalid memory access flaw. It occurs while sending messages using sendmsg(2)
to an IPv4 address over an IPv6 socket. It could result in system crash or
potentially used to gain root privileges.
A user/program could use this flaw to crash the system resulting in DoS.
Nevertheless, potential privilege escalation can not be ruled out.
Upstream fix:
-> https://git.kernel.org/linus/a963a37d384d71ad43b3e9e79d68d42fbe0901f3
Reference:
-> http://www.openwall.com/lists/oss-security/2013/07/02/3
Discussion:
Statement:
This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterp
Bugzilla
kernel: CVE-2013-2232 Kernel: ipv6: using ipv4 vs ipv6 structure during routing lookup in sendmsg [fedora-all]
bugzilla·2013-07-05·CVSS 4.9
CVE-2013-2232 [MEDIUM] kernel: CVE-2013-2232 Kernel: ipv6: using ipv4 vs ipv6 structure during routing lookup in sendmsg [fedora-all]
kernel: CVE-2013-2232 Kernel: ipv6: using ipv4 vs ipv6 structure during routing lookup in sendmsg [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availa
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a963a37d384d71ad43b3e9e79d68d42fbe0901f3http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1166.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1173.htmlhttp://www.debian.org/security/2013/dsa-2766http://www.openwall.com/lists/oss-security/2013/07/02/5http://www.ubuntu.com/usn/USN-1912-1http://www.ubuntu.com/usn/USN-1913-1http://www.ubuntu.com/usn/USN-1938-1http://www.ubuntu.com/usn/USN-1941-1http://www.ubuntu.com/usn/USN-1942-1http://www.ubuntu.com/usn/USN-1943-1http://www.ubuntu.com/usn/USN-1944-1http://www.ubuntu.com/usn/USN-1945-1http://www.ubuntu.com/usn/USN-1946-1http://www.ubuntu.com/usn/USN-1947-1https://github.com/torvalds/linux/commit/a963a37d384d71ad43b3e9e79d68d42fbe0901f3https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.10.bz2http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a963a37d384d71ad43b3e9e79d68d42fbe0901f3http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1166.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1173.htmlhttp://www.debian.org/security/2013/dsa-2766http://www.openwall.com/lists/oss-security/2013/07/02/5http://www.ubuntu.com/usn/USN-1912-1http://www.ubuntu.com/usn/USN-1913-1http://www.ubuntu.com/usn/USN-1938-1http://www.ubuntu.com/usn/USN-1941-1http://www.ubuntu.com/usn/USN-1942-1http://www.ubuntu.com/usn/USN-1943-1http://www.ubuntu.com/usn/USN-1944-1http://www.ubuntu.com/usn/USN-1945-1http://www.ubuntu.com/usn/USN-1946-1http://www.ubuntu.com/usn/USN-1947-1https://github.com/torvalds/linux/commit/a963a37d384d71ad43b3e9e79d68d42fbe0901f3https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.10.bz2
2013-07-04
Published