CVE-2013-2851
published 2013-06-07CVE-2013-2851: Format string vulnerability in the register_disk function in block/genhd.c in the Linux kernel through 3.9.4 allows local users to gain privileges by…
PriorityP425medium6CVSS 2.0
AVLACHAuSCCICAC
EPSS
0.34%
26.6th percentile
Format string vulnerability in the register_disk function in block/genhd.c in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and writing format string specifiers to /sys/module/md_mod/parameters/new_array in order to create a crafted /dev/md device name.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.9.8-1 (bookworm) | linux 3.9.8-1 (bookworm) |
| linux | linux_kernel | <= 3.9.4 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.9.8-1 | 3.9.8-1 |
| linux | linux_kernel | >= 0 < 3.9.8-1 | 3.9.8-1 |
| linux | linux_kernel | >= 0 < 3.9.8-1 | 3.9.8-1 |
| linux | linux_kernel | >= 0 < 3.9.8-1 | 3.9.8-1 |
CVSS provenance
nvdv2.06.0MEDIUMAV:L/AC:H/Au:S/C:C/I:C/A:C
osv6.0MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian6.0LOW
vendor_redhat6.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (CVE-2013-1060)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-09-06·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
Vasily Kulikov discovered a flaw in the Linux Kernel's perf tool that
allows for privilege escalation. A local user could exploit this flaw to
run commands as root when using the perf tool. (CVE-2013-1060)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local us
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local use
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local user with admini
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local user wit
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local user with admini
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-07-29·CVSS 2.1
CVE-2013-2164 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4 destination. An unprivileged local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2013-2232)
An information leak was discovered in the IPSec key_socket implementation
in the Linux kernel. An local user could exploit this flaw to examine
potentially sensitive information in kernel memory. (CVE-2013-2234)
An information leak was discovered in the Linux
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2013-07-29·CVSS 2.1
CVE-2013-2164 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
A flaw was discovered in the Linux kernel when an IPv6 socket is used to
connect to an IPv4 destination. An unprivileged local user could exploit
this flaw to cause a denial of service (system crash). (CVE-2013-2232)
An information leak was discovered in the IPSec key_socket implementation
in the Linux kernel. An local user could exploit this flaw to examine
potentially sensitive information in kernel memory. (CVE-2013-2234)
An information leak was discovered in the
Red Hat
kernel: block: passing disk names as format strings
vendor_redhat·2013-06-06·CVSS 6.0
CVE-2013-2851 [MEDIUM] kernel: block: passing disk names as format strings
kernel: block: passing disk names as format strings
Format string vulnerability in the register_disk function in block/genhd.c in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and writing format string specifiers to /sys/module/md_mod/parameters/new_array in order to create a crafted /dev/md device name.
Statement: This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5.
This issue does affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 6, and Red Hat Enterprise MRG. Future updates for Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG may address this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux
Debian
CVE-2013-2851: linux - Format string vulnerability in the register_disk function in block/genhd.c in th...
vendor_debian·2013·CVSS 6.0
CVE-2013-2851 [MEDIUM] CVE-2013-2851: linux - Format string vulnerability in the register_disk function in block/genhd.c in th...
Format string vulnerability in the register_disk function in block/genhd.c in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and writing format string specifiers to /sys/module/md_mod/parameters/new_array in order to create a crafted /dev/md device name.
Scope: local
bookworm: resolved (fixed in 3.9.8-1)
bullseye: resolved (fixed in 3.9.8-1)
forky: resolved (fixed in 3.9.8-1)
sid: resolved (fixed in 3.9.8-1)
trixie: resolved (fixed in 3.9.8-1)
GHSA
GHSA-m8m5-89h4-8cjh: Format string vulnerability in the register_disk function in block/genhd
ghsa_unreviewed·2022-05-17
CVE-2013-2851 [MEDIUM] CWE-134 GHSA-m8m5-89h4-8cjh: Format string vulnerability in the register_disk function in block/genhd
Format string vulnerability in the register_disk function in block/genhd.c in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and writing format string specifiers to /sys/module/md_mod/parameters/new_array in order to create a crafted /dev/md device name.
Kernel
block: do not pass disk names as format strings
kernel_security·2013-07-03·CVSS 6.0
CVE-2013-2851 [MEDIUM] block: do not pass disk names as format strings
block: do not pass disk names as format strings
Disk names may contain arbitrary strings, so they must not be
interpreted as format strings. It seems that only md allows arbitrary
strings to be used for disk names, but this could allow for a local
memory corruption from uid 0 into ring 0.
CVE-2013-2851
Signed-off-by: Kees Cook
Cc: Jens Axboe
Cc:
Signed-off-by: Andrew Morton
Signed-off-by: Linus Torvalds
OSV
CVE-2013-2851: Format string vulnerability in the register_disk function in block/genhd
osv·2013-06-07·CVSS 6.0
CVE-2013-2851 [MEDIUM] CVE-2013-2851: Format string vulnerability in the register_disk function in block/genhd
Format string vulnerability in the register_disk function in block/genhd.c in the Linux kernel through 3.9.4 allows local users to gain privileges by leveraging root access and writing format string specifiers to /sys/module/md_mod/parameters/new_array in order to create a crafted /dev/md device name.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-2851 kernel: block: passing disk names as format strings [fedora-all]
bugzilla·2013-06-07·CVSS 6.0
CVE-2013-2851 [MEDIUM] CVE-2013-2851 kernel: block: passing disk names as format strings [fedora-all]
CVE-2013-2851 kernel: block: passing disk names as format strings [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue af
Bugzilla
CVE-2013-2851 kernel: block: passing disk names as format strings
bugzilla·2013-05-31·CVSS 6.0
CVE-2013-2851 [MEDIUM] CVE-2013-2851 kernel: block: passing disk names as format strings
CVE-2013-2851 kernel: block: passing disk names as format strings
A flaw was found in the way certain disk names were interpreted by the Linux kernel.
Block layer uses the "disk_name" field as a format string in a number of places. While this is normally not a problem due to how disk names are created (statically or incrementally), there is currently at least one way to define nearly arbitrary names via md.
A privileged (uid 0) local user could potentially use this flaw to execute code at ring0.
Acknowledgements:
Red Hat would like to thank Kees Cook for reporting this issue.
Discussion:
Statement:
This issue does not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5.
This issue does affect the versions of the Linux kernel as shipped with Red Hat E
http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://marc.info/?l=linux-kernel&m=137055204522556&w=2http://rhn.redhat.com/errata/RHSA-2013-1645.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1783.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0284.htmlhttp://www.debian.org/security/2013/dsa-2766http://www.openwall.com/lists/oss-security/2013/06/06/13http://www.ubuntu.com/usn/USN-1912-1http://www.ubuntu.com/usn/USN-1913-1http://www.ubuntu.com/usn/USN-1941-1http://www.ubuntu.com/usn/USN-1942-1https://bugzilla.redhat.com/show_bug.cgi?id=969515http://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00004.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://marc.info/?l=linux-kernel&m=137055204522556&w=2http://rhn.redhat.com/errata/RHSA-2013-1645.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1783.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0284.htmlhttp://www.debian.org/security/2013/dsa-2766http://www.openwall.com/lists/oss-security/2013/06/06/13http://www.ubuntu.com/usn/USN-1912-1http://www.ubuntu.com/usn/USN-1913-1http://www.ubuntu.com/usn/USN-1941-1http://www.ubuntu.com/usn/USN-1942-1https://bugzilla.redhat.com/show_bug.cgi?id=969515
2013-06-07
Published