CVE-2013-2234
published 2013-07-04CVE-2013-2234: The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure…
PriorityP46low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.55%
43.4th percentile
The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify interface of an IPSec key_socket.
Affected
208 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.10.1-1 (bookworm) | linux 3.10.1-1 (bookworm) |
| linux | linux_kernel | <= 3.9.9 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_ubuntu7.8HIGH
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-09-07·CVSS 4.0
CVE-2012-5374 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 4.0
CVE-2012-5374 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 4.0
CVE-2012-5374 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service by creating a
large number of files with names that have the same CRC32 hash value.
(CVE-2012-5374)
A denial of service flaw was discovered in the Btrfs file system in the
Linux kernel. A local user could cause a denial of service (prevent file
creation) for a victim, by creating a file with a specific CRC32C hash
value in a directory important to the victim. (CVE-2012-5375)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (C
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 6.9
CVE-2013-1060 [MEDIUM] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (CVE-2013-1060)
A flaw was discovered in the Xen subsystem of the Linux kernel when it
provides read-only access to a disk that supports TRIM or SCSI UNMAP to a
guest OS. A privileged user in the guest OS could exploit this flaw to
destroy data on the disk, even though the guest OS should not be able to
write to the disk. (CVE-2013-2140)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4 destination. An unprivileged local user could exploit
this flaw to
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (CVE-2013-1060)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (CVE-2013-1060)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-05·CVSS 6.9
CVE-2013-1060 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows specified to be run as root. A local could exploit this flaw to run
commands as root when using the perf tool. user could exploit this
(CVE-2013-1060)
A flaw was discovered in the Xen subsystem of the Linux kernel when it
provides read-only access to a disk that supports TRIM or SCSI UNMAP to a
guest OS. A privileged user in the guest OS could exploit this flaw to
destroy data on the disk, even though the guest OS should not be able to
write to the disk. (CVE-2013-2140)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4 destination. An unprivileged local user could exploit
thi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-07-29·CVSS 2.1
CVE-2013-2164 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4 destination. An unprivileged local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2013-2232)
An information leak was discovered in the IPSec key_socket implementation
in the Linux kernel. An local user could exploit this flaw to examine
potentially sensitive information in kernel memory. (CVE-2013-2234)
An information leak was discovered in the Linux
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2013-07-29·CVSS 2.1
CVE-2013-2164 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4 destination. An unprivileged local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2013-2232)
An information leak was discovered in the IPSec key_socket implementation
in the Linux kernel. An local user could exploit this flaw to examine
potentially sensitive information in kernel memory. (CVE-2013-2234)
An information leak was discovered in the
Red Hat
Kernel: net: information leak in AF_KEY notify
vendor_redhat·2013-06-26·CVSS 2.1
CVE-2013-2234 [LOW] Kernel: net: information leak in AF_KEY notify
Kernel: net: information leak in AF_KEY notify
The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify interface of an IPSec key_socket.
Statement: This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2 may address this issue. This issue has been addressed for Red Hat Enterprise Linux 5 via RHSA-2013:1166 (https://rhn.redhat.com/errata/RHSA-2013-1166.html).
Debian
CVE-2013-2234: linux - The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key...
vendor_debian·2013·CVSS 2.1
CVE-2013-2234 [LOW] CVE-2013-2234: linux - The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key...
The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify interface of an IPSec key_socket.
Scope: local
bookworm: resolved (fixed in 3.10.1-1)
bullseye: resolved (fixed in 3.10.1-1)
forky: resolved (fixed in 3.10.1-1)
sid: resolved (fixed in 3.10.1-1)
trixie: resolved (fixed in 3.10.1-1)
GHSA
GHSA-38qj-gfvh-c5q6: The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key
ghsa_unreviewed·2022-05-17
CVE-2013-2234 [LOW] CWE-119 GHSA-38qj-gfvh-c5q6: The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key
The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify interface of an IPSec key_socket.
OSV
CVE-2013-2234: The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key
osv·2013-07-04·CVSS 2.1
CVE-2013-2234 [LOW] CVE-2013-2234: The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key
The (1) key_notify_sa_flush and (2) key_notify_policy_flush functions in net/key/af_key.c in the Linux kernel before 3.10 do not initialize certain structure members, which allows local users to obtain sensitive information from kernel heap memory by reading a broadcast message from the notify interface of an IPSec key_socket.
No detection rules found.
No public exploits indexed.
Bugzilla
kernel: CVE-2013-2234 Kernel: net: information leak in AF_KEY notify [fedora-all]
bugzilla·2013-07-03·CVSS 2.1
CVE-2013-2234 [LOW] kernel: CVE-2013-2234 Kernel: net: information leak in AF_KEY notify [fedora-all]
kernel: CVE-2013-2234 Kernel: net: information leak in AF_KEY notify [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
Bugzilla
CVE-2013-2234 Kernel: net: information leak in AF_KEY notify
bugzilla·2013-07-03·CVSS 2.1
CVE-2013-2234 [LOW] CVE-2013-2234 Kernel: net: information leak in AF_KEY notify
CVE-2013-2234 Kernel: net: information leak in AF_KEY notify
Linux kernel built with the IPSec key_socket support(CONFIG_NET_KEY=m) is
vulnerable to an information leakage flaw. It occurs while using key_socket's
notify interface.
A user/program able to access the PF_KEY key_sockets could use this flaw to
leak kernel memory bytes.
Upstream fix:
-> https://git.kernel.org/linus/a5cc68f3d63306d0d288f31edfc2ae6ef8ecd887
Reference:
-> http://www.openwall.com/lists/oss-security/2013/07/01/5
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 981007]
---
kernel-3.9.9-301.fc19 has been pushed to the Fedora 19 stable repository. If problems still persist, please make note of it in this bug report.
---
kernel-3.9.9-201.fc18 has been pushed to the Fedora 18 st
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a5cc68f3d63306d0d288f31edfc2ae6ef8ecd887http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1166.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1645.htmlhttp://www.debian.org/security/2013/dsa-2766http://www.openwall.com/lists/oss-security/2013/07/02/7http://www.ubuntu.com/usn/USN-1912-1http://www.ubuntu.com/usn/USN-1913-1http://www.ubuntu.com/usn/USN-1938-1http://www.ubuntu.com/usn/USN-1941-1http://www.ubuntu.com/usn/USN-1942-1http://www.ubuntu.com/usn/USN-1943-1http://www.ubuntu.com/usn/USN-1944-1http://www.ubuntu.com/usn/USN-1945-1http://www.ubuntu.com/usn/USN-1946-1http://www.ubuntu.com/usn/USN-1947-1https://bugzilla.redhat.com/show_bug.cgi?id=980995https://github.com/torvalds/linux/commit/a5cc68f3d63306d0d288f31edfc2ae6ef8ecd887https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.10.bz2http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a5cc68f3d63306d0d288f31edfc2ae6ef8ecd887http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1166.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1645.htmlhttp://www.debian.org/security/2013/dsa-2766http://www.openwall.com/lists/oss-security/2013/07/02/7http://www.ubuntu.com/usn/USN-1912-1http://www.ubuntu.com/usn/USN-1913-1http://www.ubuntu.com/usn/USN-1938-1http://www.ubuntu.com/usn/USN-1941-1http://www.ubuntu.com/usn/USN-1942-1http://www.ubuntu.com/usn/USN-1943-1http://www.ubuntu.com/usn/USN-1944-1http://www.ubuntu.com/usn/USN-1945-1http://www.ubuntu.com/usn/USN-1946-1http://www.ubuntu.com/usn/USN-1947-1https://bugzilla.redhat.com/show_bug.cgi?id=980995https://github.com/torvalds/linux/commit/a5cc68f3d63306d0d288f31edfc2ae6ef8ecd887https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.10.bz2
2013-07-04
Published