CVE-2013-2898
published 2013-09-16CVE-2013-2898: drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows…
PriorityP48low1.9CVSS 2.0
AVLACMAuNCPINAN
EPSS
0.36%
29.4th percentile
drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows physically proximate attackers to obtain sensitive information from kernel memory via a crafted device.
Affected
228 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.10.11-1 (bookworm) | linux 3.10.11-1 (bookworm) |
| linux | linux_kernel | <= 3.11 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.01.9LOWAV:L/AC:M/Au:N/C:P/I:N/A:N
osv1.9LOW
vendor_ubuntu2.1LOW
vendor_debian1.9LOW
vendor_redhat1.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-10-22·CVSS 2.1
CVE-2013-2237 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the Linux kernel when reading
broadcast messages from the notify_policy interface of the IPSec
key_socket. A local user could exploit this flaw to examine potentially
sensitive information in kernel memory. (CVE-2013-2237)
Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit this flaw
to execute arbitrary code or cause a denial of service (heap memory
corruption) via a specially crafted device that provides an invalid Report
ID. (CVE-2013-2888)
Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kerenl when CONFIG_HID_PANTHERLORD is ena
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-10-22·CVSS 2.1
CVE-2013-2237 [LOW] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the Linux kernel when reading
broadcast messages from the notify_policy interface of the IPSec
key_socket. A local user could exploit this flaw to examine potentially
sensitive information in kernel memory. (CVE-2013-2237)
Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit this flaw
to execute arbitrary code or cause a denial of service (heap memory
corruption) via a specially crafted device that provides an invalid Report
ID. (CVE-2013-2888)
Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kerenl when CONFIG_HID_PANTH
Red Hat
Kernel: HID: sensor-hub: memory leak flaw
vendor_redhat·2013-08-29·CVSS 1.9
CVE-2013-2898 [LOW] CWE-401 Kernel: HID: sensor-hub: memory leak flaw
Kernel: HID: sensor-hub: memory leak flaw
drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows physically proximate attackers to obtain sensitive information from kernel memory via a crafted device.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-2898: linux - drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in th...
vendor_debian·2013·CVSS 1.9
CVE-2013-2898 [LOW] CVE-2013-2898: linux - drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in th...
drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows physically proximate attackers to obtain sensitive information from kernel memory via a crafted device.
Scope: local
bookworm: resolved (fixed in 3.10.11-1)
bullseye: resolved (fixed in 3.10.11-1)
forky: resolved (fixed in 3.10.11-1)
sid: resolved (fixed in 3.10.11-1)
trixie: resolved (fixed in 3.10.11-1)
GHSA
GHSA-566v-9345-g5hf: drivers/hid/hid-sensor-hub
ghsa_unreviewed·2022-05-17
CVE-2013-2898 [LOW] CWE-20 GHSA-566v-9345-g5hf: drivers/hid/hid-sensor-hub
drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows physically proximate attackers to obtain sensitive information from kernel memory via a crafted device.
OSV
CVE-2013-2898: drivers/hid/hid-sensor-hub
osv·2013-09-16·CVSS 1.9
CVE-2013-2898 [LOW] CVE-2013-2898: drivers/hid/hid-sensor-hub
drivers/hid/hid-sensor-hub.c in the Human Interface Device (HID) subsystem in the Linux kernel through 3.11, when CONFIG_HID_SENSOR_HUB is enabled, allows physically proximate attackers to obtain sensitive information from kernel memory via a crafted device.
Kernel
Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jikos/hid
kernel_security·2013-09-06·CVSS 6.2
CVE-2013-2888 [MEDIUM] Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jikos/hid
Merge branch 'for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/jikos/hid
Pull HID updates from Jiri Kosina:
"Highlights:
- conversion of HID subsystem to use devm-based resource management,
from Benjamin Tissoires
- i2c-hid support for DT bindings, from Benjamin Tissoires
- much improved support for Win8-multitouch devices, from Benjamin
Tissoires
- cleanup of core code using common hidinput_input_event(), from
David Herrmann
- fix for bug in implement() access to the bit stream (causing oops)
that has been present in the code for ages, but devices that are
able to trigger it have started to appear only now, from Jiri
Kosina
- fixes for CVE-2013-2899, CVE-2013-2898, CVE-2013-2896,
CVE-2013-2892, CVE-2013-2888 (all triggerable only by specially
crafted malicious HW devices
Kernel
HID: sensor-hub: validate feature report details
kernel_security·2013-08-28·CVSS 1.9
CVE-2013-2898 [LOW] HID: sensor-hub: validate feature report details
HID: sensor-hub: validate feature report details
A HID device could send a malicious feature report that would cause the
sensor-hub HID driver to read past the end of heap allocation, leaking
kernel memory contents to the caller.
CVE-2013-2898
Signed-off-by: Kees Cook
Cc: [email protected]
Reviewed-by: Mika Westerberg
Signed-off-by: Jiri Kosina
No detection rules found.
No public exploits indexed.
http://marc.info/?l=linux-input&m=137772191114645&w=1http://openwall.com/lists/oss-security/2013/08/28/13http://www.ubuntu.com/usn/USN-1995-1http://www.ubuntu.com/usn/USN-1998-1http://marc.info/?l=linux-input&m=137772191114645&w=1http://openwall.com/lists/oss-security/2013/08/28/13http://www.ubuntu.com/usn/USN-1995-1http://www.ubuntu.com/usn/USN-1998-1
2013-09-16
Published