cbcvebase.
CVE-2013-2850
published 2013-06-07

CVE-2013-2850: Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in…

PriorityP345high7.9CVSS 2.0
AVAACMAuNCCICAC
EPSS
7.31%
93.7th percentile
Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possibly execute arbitrary code via a long key that is not properly handled during construction of an error-response packet.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.9.4-1 (bookworm)linux 3.9.4-1 (bookworm)
linuxlinux_kernel>= 0 < 3.9.4-13.9.4-1
linuxlinux_kernel>= 0 < 3.9.4-13.9.4-1
linuxlinux_kernel>= 0 < 3.9.4-13.9.4-1
linuxlinux_kernel>= 0 < 3.9.4-13.9.4-1
linuxlinux_kernel>= 0 < 3.11.0-12.193.11.0-12.19
linuxlinux_kernel>= 0 < 4.2.0-16.194.2.0-16.19
linuxlinux_kernel>= 3.1 < 3.2.473.2.47
linuxlinux_kernel>= 3.3 < 3.4.483.4.48
linuxlinux_kernel>= 3.5 < 3.9.53.9.5

CVSS provenance

nvdv2.07.9HIGHAV:A/AC:M/Au:N/C:C/I:C/A:C
osv7.9HIGH
vendor_ubuntu8.4HIGH
vendor_debian7.9HIGH
vendor_redhat7.9HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.