CVE-2013-2930
published 2013-12-09CVE-2013-2930: The perf_trace_event_perm function in kernel/trace/trace_event_perf.c in the Linux kernel before 3.12.2 does not properly restrict access to the perf…
PriorityP411low3.6CVSS 2.0
AVLACLAuNCPIPAN
EPSS
0.66%
48.5th percentile
The perf_trace_event_perm function in kernel/trace/trace_event_perf.c in the Linux kernel before 3.12.2 does not properly restrict access to the perf subsystem, which allows local users to enable function tracing via a crafted application.
Affected
243 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.11.8-1 (bookworm) | linux 3.11.8-1 (bookworm) |
| linux | linux_kernel | <= 3.12.1 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.03.6LOWAV:L/AC:L/Au:N/C:P/I:P/A:N
osv3.6LOW
vendor_debian3.6LOW
vendor_redhat3.6LOW
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-566q-w58c-q678: The perf_trace_event_perm function in kernel/trace/trace_event_perf
ghsa_unreviewed·2022-05-17
CVE-2013-2930 [LOW] GHSA-566q-w58c-q678: The perf_trace_event_perm function in kernel/trace/trace_event_perf
The perf_trace_event_perm function in kernel/trace/trace_event_perf.c in the Linux kernel before 3.12.2 does not properly restrict access to the perf subsystem, which allows local users to enable function tracing via a crafted application.
OSV
CVE-2013-2930: The perf_trace_event_perm function in kernel/trace/trace_event_perf
osv·2013-12-09·CVSS 3.6
CVE-2013-2930 [LOW] CVE-2013-2930: The perf_trace_event_perm function in kernel/trace/trace_event_perf
The perf_trace_event_perm function in kernel/trace/trace_event_perf.c in the Linux kernel before 3.12.2 does not properly restrict access to the perf subsystem, which allows local users to enable function tracing via a crafted application.
Kernel
perf/ftrace: Fix paranoid level for enabling function tracer
kernel_security·2013-11-05·CVSS 3.6
CVE-2013-2930 [LOW] perf/ftrace: Fix paranoid level for enabling function tracer
perf/ftrace: Fix paranoid level for enabling function tracer
The current default perf paranoid level is "1" which has
"perf_paranoid_kernel()" return false, and giving any operations that
use it, access to normal users. Unfortunately, this includes function
tracing and normal users should not be allowed to enable function
tracing by default.
The proper level is defined at "-1" (full perf access), which
"perf_paranoid_tracepoint_raw()" will only give access to. Use that
check instead for enabling function tracing.
Reported-by: Dave Jones
Reported-by: Vince Weaver
Tested-by: Vince Weaver
Cc: Peter Zijlstra
Cc: Ingo Molnar
Cc: Jiri Olsa
Cc: Frederic Weisbecker
Cc: [email protected] # 3.4+
CVE: CVE-2013-2930
Fixes: ced39002f5ea ("ftrace, perf: Add support to use function tracepoint in
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
A flaw in the handling of memory region
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in t
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.6
CVE-2013-2930 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguch
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network f
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.6
CVE-2013-2930 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.6
CVE-2013-2930 [LOW] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
Multiple integer overflow flaws were discover
Red Hat
kernel: perf/ftrace: insufficient check in perf_trace_event_perm()
vendor_redhat·2013-12-09·CVSS 3.6
CVE-2013-2930 [LOW] kernel: perf/ftrace: insufficient check in perf_trace_event_perm()
kernel: perf/ftrace: insufficient check in perf_trace_event_perm()
The perf_trace_event_perm function in kernel/trace/trace_event_perf.c in the Linux kernel before 3.12.2 does not properly restrict access to the perf subsystem, which allows local users to enable function tracing via a crafted application.
Statement: This issue does not affect the version of the kernel package as shipped with Red Hat Enterprise Linux 5 and 6.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-2930: linux - The perf_trace_event_perm function in kernel/trace/trace_event_perf.c in the Lin...
vendor_debian·2013·CVSS 3.6
CVE-2013-2930 [LOW] CVE-2013-2930: linux - The perf_trace_event_perm function in kernel/trace/trace_event_perf.c in the Lin...
The perf_trace_event_perm function in kernel/trace/trace_event_perf.c in the Linux kernel before 3.12.2 does not properly restrict access to the perf subsystem, which allows local users to enable function tracing via a crafted application.
Scope: local
bookworm: resolved (fixed in 3.11.8-1)
bullseye: resolved (fixed in 3.11.8-1)
forky: resolved (fixed in 3.11.8-1)
sid: resolved (fixed in 3.11.8-1)
trixie: resolved (fixed in 3.11.8-1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=12ae030d54ef250706da5642fc7697cc60ad0df7http://rhn.redhat.com/errata/RHSA-2014-0100.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.12.2http://www.ubuntu.com/usn/USN-2068-1http://www.ubuntu.com/usn/USN-2070-1http://www.ubuntu.com/usn/USN-2071-1http://www.ubuntu.com/usn/USN-2072-1http://www.ubuntu.com/usn/USN-2074-1http://www.ubuntu.com/usn/USN-2075-1http://www.ubuntu.com/usn/USN-2076-1http://www.ubuntu.com/usn/USN-2112-1https://github.com/torvalds/linux/commit/12ae030d54ef250706da5642fc7697cc60ad0df7http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=12ae030d54ef250706da5642fc7697cc60ad0df7http://rhn.redhat.com/errata/RHSA-2014-0100.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.12.2http://www.ubuntu.com/usn/USN-2068-1http://www.ubuntu.com/usn/USN-2070-1http://www.ubuntu.com/usn/USN-2071-1http://www.ubuntu.com/usn/USN-2072-1http://www.ubuntu.com/usn/USN-2074-1http://www.ubuntu.com/usn/USN-2075-1http://www.ubuntu.com/usn/USN-2076-1http://www.ubuntu.com/usn/USN-2112-1https://github.com/torvalds/linux/commit/12ae030d54ef250706da5642fc7697cc60ad0df7
2013-12-09
Published