CVE-2013-3076
published 2013-04-22CVE-2013-3076: The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCCINAN
EPSS
0.35%
28.4th percentile
The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg function in crypto/algif_hash.c and the skcipher_recvmsg function in crypto/algif_skcipher.c.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.8.11-1 (bookworm) | linux 3.8.11-1 (bookworm) |
| linux | linux_kernel | <= 3.9 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.8.11-1 | 3.8.11-1 |
| linux | linux_kernel | >= 0 < 3.8.11-1 | 3.8.11-1 |
| linux | linux_kernel | >= 0 < 3.8.11-1 | 3.8.11-1 |
| linux | linux_kernel | >= 0 < 3.8.11-1 | 3.8.11-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:C/I:N/A:N
osv4.9MEDIUM
vendor_ubuntu8.4HIGH
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-06-14·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
A flaw was discovered in the Linux kernel's perf events subsystem for Intel
Sandy Bridge and Ivy Bridge processors. A local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2013-2146)
An information leak was discovered in the Linux kernel's crypto API. A
local user could exploit this flaw to examine potentially sensitive
information from the kernel's stack memory. (CVE-2013-3076)
An information leak was dis
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-06-14·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discover an error in the Linux kernel's credential handling
on unix sockets. A local user could exploit this flaw to gain
administrative privileges. (CVE-2013-1979)
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used from compat processes. A local user could exploit
this flaw to examine potentially sensitive kernel memory. (CVE-2013-2141)
A flaw was discovered in
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-06-14·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Kees Cook discovered a flaw in the Linux kernel's iSCSI subsystem. A remote
unauthenticated attacker could exploit this flaw to cause a denial of
service (system crash) or potentially gain administrative privileges.
(CVE-2013-2850)
Andy Lutomirski discover an error in the Linux kernel's credential handling
on unix sockets. A local user could exploit this flaw to gain
administrative privileges. (CVE-2013-1979)
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
An information leak
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-06-14·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Kees Cook discovered a flaw in the Linux kernel's iSCSI subsystem. A remote
unauthenticated attacker could exploit this flaw to cause a denial of
service (system crash) or potentially gain administrative privileges.
(CVE-2013-2850)
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
A flaw was discovered in the Linux kernel's perf events subsystem for Intel
Sandy Bridge and Ivy Bridge processors. A local user could exploit this
flaw to cause a denial of service (system crash). (CV
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-06-14·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Kees Cook discovered a flaw in the Linux kernel's iSCSI subsystem. A remote
unauthenticated attacker could exploit this flaw to cause a denial of
service (system crash) or potentially gain administrative privileges.
(CVE-2013-2850)
Andy Lutomirski discover an error in the Linux kernel's credential handling
on unix sockets. A local user could exploit this flaw to gain
administrative privileges. (CVE-2013-1979)
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
An information leak
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-06-14·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discover an error in the Linux kernel's credential handling
on unix sockets. A local user could exploit this flaw to gain
administrative privileges. (CVE-2013-1979)
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used from compat processes. A local user could exploit
this flaw to examine potentially sensitive kernel memory. (CVE-2013-2141)
A flaw was discovered in the Linux ker
Ubuntu
Linux kernel (Raring HWE) vulnerability
vendor_ubuntu·2013-05-31·CVSS 8.4
CVE-2013-2094 [HIGH] Linux kernel (Raring HWE) vulnerability
Title: Linux kernel (Raring HWE) vulnerability
Summary: Several security issues were fixed in the kernel.
Kees Cook discovered a flaw in the Linux kernel's iSCSI subsystem. A remote
unauthenticated attacker could exploit this flaw to cause a denial of
service (system crash) or potentially gain administrative privileges.
(CVE-2013-2850)
An flaw was discovered in the Linux kernel's perf_events interface. A local
user could exploit this flaw to escalate privileges on the system.
(CVE-2013-2094)
An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used from compat processes. A local user could exploit
this flaw to examine potentially sensitive kernel memory. (CVE-2013-2141)
A flaw was discovered in the Linux kernel's perf events subsystem for Intel
S
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-05-24·CVSS 2.1
CVE-2013-2141 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used from compat processes. A local user could exploit
this flaw to examine potentially sensitive kernel memory. (CVE-2013-2141)
A flaw was discovered in the Linux kernel's perf events subsystem for Intel
Sandy Bridge and Ivy Bridge processors. A local user could exploit this
flaw to cause a denial of service (system crash). (CVE-2013-2146)
An information leak was discovered in the Linux kernel's crypto API. A
local user could exploit this flaw to examine potentially sensitive
information from the kernel's stack memory. (CVE-2013-3076)
An information leak was discovered in the Linux kernel's rcvmsg pa
Red Hat
Kernel: crypto: algif - suppress sending source address information in recvmsg
vendor_redhat·2013-04-07·CVSS 4.9
CVE-2013-3076 [MEDIUM] Kernel: crypto: algif - suppress sending source address information in recvmsg
Kernel: crypto: algif - suppress sending source address information in recvmsg
The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg function in crypto/algif_hash.c and the skcipher_recvmsg function in crypto/algif_skcipher.c.
Statement: This issue does not affect the versions of Linux kernel as shipped with
Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6.
This issue affects the version of the kernel package as shipped with
Red Hat Enterprise MRG 2. Future kernel updates for Red Hat Enterprise MRG 2
may address this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affecte
Debian
CVE-2013-3076: linux - The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain l...
vendor_debian·2013·CVSS 4.9
CVE-2013-3076 [MEDIUM] CVE-2013-3076: linux - The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain l...
The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg function in crypto/algif_hash.c and the skcipher_recvmsg function in crypto/algif_skcipher.c.
Scope: local
bookworm: resolved (fixed in 3.8.11-1)
bullseye: resolved (fixed in 3.8.11-1)
forky: resolved (fixed in 3.8.11-1)
sid: resolved (fixed in 3.8.11-1)
trixie: resolved (fixed in 3.8.11-1)
GHSA
GHSA-37h3-2fhg-m9qh: The crypto API in the Linux kernel through 3
ghsa_unreviewed·2022-05-17
CVE-2013-3076 [MEDIUM] CWE-200 GHSA-37h3-2fhg-m9qh: The crypto API in the Linux kernel through 3
The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg function in crypto/algif_hash.c and the skcipher_recvmsg function in crypto/algif_skcipher.c.
OSV
CVE-2013-3076: The crypto API in the Linux kernel through 3
osv·2013-04-22·CVSS 4.9
CVE-2013-3076 [MEDIUM] CVE-2013-3076: The crypto API in the Linux kernel through 3
The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg function in crypto/algif_hash.c and the skcipher_recvmsg function in crypto/algif_skcipher.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-3076 Kernel: crypto: algif - suppress sending source address information in recvmsg
bugzilla·2013-04-24·CVSS 4.9
CVE-2013-3076 [MEDIUM] CVE-2013-3076 Kernel: crypto: algif - suppress sending source address information in recvmsg
CVE-2013-3076 Kernel: crypto: algif - suppress sending source address information in recvmsg
Linux kernel built with the User-space interface for hash algorithms
(CONFIG_CRYPTO_USER_API_HASH) and User-space interface for symmetric key
cipher algorithms (CONFIG_CRYPTO_USER_API_SKCIPHER) support is vulnerable
to an information leakage flaw. It occurs while receiving messages via
recvmsg(2) call.
A user/program could use this flaw to leak kernel memory bytes.
Upstream fix:
-> http://git.kernel.org/linus/72a763d805a48ac8c0bf48fdb510e84c12de51fe
Reference:
-> http://www.openwall.com/lists/oss-security/2013/04/14/3
Discussion:
Statement:
This issue does not affect the versions of Linux kernel as shipped with
Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6.
This issue affects th
Bugzilla
CVE-2013-3076 Kernel: crypto: algif - suppress sending source address information in recvmsg [fedora-all]
bugzilla·2013-04-24·CVSS 4.9
CVE-2013-3076 [MEDIUM] CVE-2013-3076 Kernel: crypto: algif - suppress sending source address information in recvmsg [fedora-all]
CVE-2013-3076 Kernel: crypto: algif - suppress sending source address information in recvmsg [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
http://lists.fedoraproject.org/pipermail/package-announce/2013-April/103750.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/104480.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.htmlhttp://www.openwall.com/lists/oss-security/2013/04/14/3http://www.ubuntu.com/usn/USN-1837-1https://github.com/torvalds/linux/commit/72a763d805a48ac8c0bf48fdb510e84c12de51fehttp://lists.fedoraproject.org/pipermail/package-announce/2013-April/103750.htmlhttp://lists.fedoraproject.org/pipermail/package-announce/2013-May/104480.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00016.htmlhttp://lists.opensuse.org/opensuse-security-announce/2013-07/msg00018.htmlhttp://www.openwall.com/lists/oss-security/2013/04/14/3http://www.ubuntu.com/usn/USN-1837-1https://github.com/torvalds/linux/commit/72a763d805a48ac8c0bf48fdb510e84c12de51fe
2013-04-22
Published