CVE-2013-2850
published 2013-06-07CVE-2013-2850: Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in…
PriorityP345high7.9CVSS 2.0
AVAACMAuNCCICAC
EPSS
7.31%
93.7th percentile
Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possibly execute arbitrary code via a long key that is not properly handled during construction of an error-response packet.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.9.4-1 (bookworm) | linux 3.9.4-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.9.4-1 | 3.9.4-1 |
| linux | linux_kernel | >= 0 < 3.9.4-1 | 3.9.4-1 |
| linux | linux_kernel | >= 0 < 3.9.4-1 | 3.9.4-1 |
| linux | linux_kernel | >= 0 < 3.9.4-1 | 3.9.4-1 |
| linux | linux_kernel | >= 0 < 3.11.0-12.19 | 3.11.0-12.19 |
| linux | linux_kernel | >= 0 < 4.2.0-16.19 | 4.2.0-16.19 |
| linux | linux_kernel | >= 3.1 < 3.2.47 | 3.2.47 |
| linux | linux_kernel | >= 3.3 < 3.4.48 | 3.4.48 |
| linux | linux_kernel | >= 3.5 < 3.9.5 | 3.9.5 |
CVSS provenance
nvdv2.07.9HIGHAV:A/AC:M/Au:N/C:C/I:C/A:C
osv7.9HIGH
vendor_ubuntu8.4HIGH
vendor_debian7.9HIGH
vendor_redhat7.9HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-06-14·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Kees Cook discovered a flaw in the Linux kernel's iSCSI subsystem. A remote
unauthenticated attacker could exploit this flaw to cause a denial of
service (system crash) or potentially gain administrative privileges.
(CVE-2013-2850)
Andy Lutomirski discover an error in the Linux kernel's credential handling
on unix sockets. A local user could exploit this flaw to gain
administrative privileges. (CVE-2013-1979)
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
An information leak
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-06-14·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Kees Cook discovered a flaw in the Linux kernel's iSCSI subsystem. A remote
unauthenticated attacker could exploit this flaw to cause a denial of
service (system crash) or potentially gain administrative privileges.
(CVE-2013-2850)
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
A flaw was discovered in the Linux kernel's perf events subsystem for Intel
Sandy Bridge and Ivy Bridge processors. A local user could exploit this
flaw to cause a denial of service (system crash). (CV
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-06-14·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Kees Cook discovered a flaw in the Linux kernel's iSCSI subsystem. A remote
unauthenticated attacker could exploit this flaw to cause a denial of
service (system crash) or potentially gain administrative privileges.
(CVE-2013-2850)
Andy Lutomirski discover an error in the Linux kernel's credential handling
on unix sockets. A local user could exploit this flaw to gain
administrative privileges. (CVE-2013-1979)
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
An information leak
Ubuntu
Linux kernel (Raring HWE) vulnerability
vendor_ubuntu·2013-05-31·CVSS 8.4
CVE-2013-2094 [HIGH] Linux kernel (Raring HWE) vulnerability
Title: Linux kernel (Raring HWE) vulnerability
Summary: Several security issues were fixed in the kernel.
Kees Cook discovered a flaw in the Linux kernel's iSCSI subsystem. A remote
unauthenticated attacker could exploit this flaw to cause a denial of
service (system crash) or potentially gain administrative privileges.
(CVE-2013-2850)
An flaw was discovered in the Linux kernel's perf_events interface. A local
user could exploit this flaw to escalate privileges on the system.
(CVE-2013-2094)
An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used from compat processes. A local user could exploit
this flaw to examine potentially sensitive kernel memory. (CVE-2013-2141)
A flaw was discovered in the Linux kernel's perf events subsystem for Intel
S
Red Hat
kernel: iscsi-target: heap buffer overflow on large key error
vendor_redhat·2013-05-30·CVSS 7.9
CVE-2013-2850 [HIGH] CWE-122 kernel: iscsi-target: heap buffer overflow on large key error
kernel: iscsi-target: heap buffer overflow on large key error
Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possibly execute arbitrary code via a long key that is not properly handled during construction of an error-response packet.
Statement: This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5 and 6 as those versions do not provide support for in-kernel iSCSI target.
Future kernel updates in Red Hat Enterprise Linux MRG 2 may address this flaw.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Packag
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2013-05-30
CVE-2013-2850 Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash or run programs as an administrator if
it received specially crafted network traffic.
Kees Cook discovered a flaw in the Linux kernel's iSCSI subsystem. A remote
unauthenticated attacker could exploit this flaw to cause a denial of
service (system crash) or potentially gain administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get modules which wo
Ubuntu
Linux kernel (Quantal HWE) vulnerability
vendor_ubuntu·2013-05-30
CVE-2013-2850 Linux kernel (Quantal HWE) vulnerability
Title: Linux kernel (Quantal HWE) vulnerability
Summary: The system could be made to crash or run programs as an administrator if
it received specially crafted network traffic.
Kees Cook discovered a flaw in the Linux kernel's iSCSI subsystem. A remote
unauthenticated attacker could exploit this flaw to cause a denial of
service (system crash) or potentially gain administrative privileges.
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules you might have installed. If
you use linux-restricted-modules, you have to update that package as
well to get mo
Debian
CVE-2013-2850: linux - Heap-based buffer overflow in the iscsi_add_notunderstood_response function in d...
vendor_debian·2013·CVSS 7.9
CVE-2013-2850 [HIGH] CVE-2013-2850: linux - Heap-based buffer overflow in the iscsi_add_notunderstood_response function in d...
Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possibly execute arbitrary code via a long key that is not properly handled during construction of an error-response packet.
Scope: local
bookworm: resolved (fixed in 3.9.4-1)
bullseye: resolved (fixed in 3.9.4-1)
forky: resolved (fixed in 3.9.4-1)
sid: resolved (fixed in 3.9.4-1)
trixie: resolved (fixed in 3.9.4-1)
GHSA
GHSA-88vm-8xxr-9jwq: Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters
ghsa_unreviewed·2022-05-17
CVE-2013-2850 [HIGH] CWE-119 GHSA-88vm-8xxr-9jwq: Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters
Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possibly execute arbitrary code via a long key that is not properly handled during construction of an error-response packet.
OSV
CVE-2013-2850: Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters
osv·2013-06-07·CVSS 7.9
CVE-2013-2850 [HIGH] CVE-2013-2850: Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters
Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possibly execute arbitrary code via a long key that is not properly handled during construction of an error-response packet.
OSV
CVE-2013-2850: Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters
osv·2013-05-30·CVSS 7.9
CVE-2013-2850 [HIGH] CVE-2013-2850: Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters
Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possibly execute arbitrary code via a long key that is not properly handled during construction of an error-response packet. A reproduction case requires patching open-iscsi to send overly large keys. Performing discovery in a loop will Oops the remote server. Attached is a proposed fix, and the patch I used in open-iscsi to trigger it. Thanks in advance for your cooperation in coordinating a fix for this issue,
Kernel
iscsi-target: fix heap buffer overflow on error
kernel_security·2013-05-23·CVSS 7.9
CVE-2013-2850 [HIGH] iscsi-target: fix heap buffer overflow on error
iscsi-target: fix heap buffer overflow on error
If a key was larger than 64 bytes, as checked by iscsi_check_key(), the
error response packet, generated by iscsi_add_notunderstood_response(),
would still attempt to copy the entire key into the packet, overflowing
the structure on the heap.
Remote preauthentication kernel memory corruption was possible if a
target was configured and listening on the network.
CVE-2013-2850
Signed-off-by: Kees Cook
Cc: [email protected]
Signed-off-by: Nicholas Bellinger
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2850 kernel: iscsi-target: heap buffer overflow on large key error [fedora-all]
bugzilla·2013-05-31·CVSS 7.9
CVE-2013-2850 [HIGH] CVE-2013-2850 kernel: iscsi-target: heap buffer overflow on large key error [fedora-all]
CVE-2013-2850 kernel: iscsi-target: heap buffer overflow on large key error [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
Bugzilla
CVE-2013-2850 kernel: iscsi-target: heap buffer overflow on large key error
bugzilla·2013-05-28·CVSS 7.9
CVE-2013-2850 [HIGH] CVE-2013-2850 kernel: iscsi-target: heap buffer overflow on large key error
CVE-2013-2850 kernel: iscsi-target: heap buffer overflow on large key error
A flaw was found in the way Linux kernel's iSCSI target processed large keys. If a key was larger than 64 bytes, as checked by iscsi_check_key(), the error response packet, generated by iscsi_add_notunderstood_response(), would still attempt to copy the entire key into the packet, overflowing the structure on the heap.
A remote attacker could use this flaw to escalate their privileges on the system.
Acknowledgements:
Red Hat would like to thank Kees Cook for reporting this issue.
Discussion:
Statement:
This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5 and 6 as those versions do not provide support for in-kernel iSCSI target.
Future kernel updates in Red H
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cea4dcfdad926a27a18e188720efe0f2c9403456http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00018.htmlhttp://www.openwall.com/lists/oss-security/2013/06/01/2http://www.ubuntu.com/usn/USN-1844-1http://www.ubuntu.com/usn/USN-1845-1http://www.ubuntu.com/usn/USN-1846-1http://www.ubuntu.com/usn/USN-1847-1https://bugzilla.redhat.com/show_bug.cgi?id=968036https://github.com/torvalds/linux/commit/cea4dcfdad926a27a18e188720efe0f2c9403456http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=cea4dcfdad926a27a18e188720efe0f2c9403456http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00011.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00017.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-06/msg00018.htmlhttp://www.openwall.com/lists/oss-security/2013/06/01/2http://www.ubuntu.com/usn/USN-1844-1http://www.ubuntu.com/usn/USN-1845-1http://www.ubuntu.com/usn/USN-1846-1http://www.ubuntu.com/usn/USN-1847-1https://bugzilla.redhat.com/show_bug.cgi?id=968036https://github.com/torvalds/linux/commit/cea4dcfdad926a27a18e188720efe0f2c9403456
2013-06-07
Published