CVE-2013-3301
published 2013-04-29CVE-2013-3301: The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or…
PriorityP428high7.2CVSS 2.0
AVLACLAuNCCICAC
EXPLOIT
EPSS
0.98%
58.4th percentile
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.8.11-1 (bookworm) | linux 3.8.11-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.8.11-1 | 3.8.11-1 |
| linux | linux_kernel | >= 0 < 3.8.11-1 | 3.8.11-1 |
| linux | linux_kernel | >= 0 < 3.8.11-1 | 3.8.11-1 |
| linux | linux_kernel | >= 0 < 3.8.11-1 | 3.8.11-1 |
| linux | linux_kernel | >= 3.1 < 3.2.44 | 3.2.44 |
| linux | linux_kernel | >= 3.3 < 3.4.49 | 3.4.49 |
| linux | linux_kernel | >= 3.5 < 3.8.8 | 3.8.8 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_mrg | — | — |
| suse | linux_enterprise_desktop | — | — |
| suse | linux_enterprise_high_availability_extension | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2LOW
vendor_redhat7.2HIGH
vendor_ubuntu4.4MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-05-30·CVSS 4.4
CVE-2013-1929 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An flaw was discovered in the Linux kernel's perf_events interface. A local
user could exploit this flaw to escalate privileges on the system.
(CVE-2013-2094)
A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet
driver for the Linux kernel. A local user could exploit this flaw to cause
a denial of service (crash the system) or potentially escalate privileges
on the system. (CVE-2013-1929)
A flaw was discovered in the Linux kernel's ftrace subsystem interface. A
local user could exploit this flaw to cause a denial of service (system
crash). (CVE-2013-3301)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary cha
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-05-28·CVSS 4.4
CVE-2013-1929 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An flaw was discovered in the Linux kernel's perf_events interface. A local
user could exploit this flaw to escalate privileges on the system.
(CVE-2013-2094)
Andy Lutomirski discover an error in the Linux kernel's credential handling
on unix sockets. A local user could exploit this flaw to gain
administrative privileges. (CVE-2013-1979)
A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet
driver for the Linux kernel. A local user could exploit this flaw to cause
a denial of service (crash the system) or potentially escalate privileges
on the system. (CVE-2013-1929)
An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-05-24·CVSS 4.4
CVE-2013-1929 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet
driver for the Linux kernel. A local user could exploit this flaw to cause
a denial of service (crash the system) or potentially escalate privileges
on the system. (CVE-2013-1929)
A flaw was discovered in the Linux kernel's ftrace subsystem interface. A
local user could exploit this flaw to cause a denial of service (system
crash). (CVE-2013-3301)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third part
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-05-24·CVSS 4.4
CVE-2013-1929 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet
driver for the Linux kernel. A local user could exploit this flaw to cause
a denial of service (crash the system) or potentially escalate privileges
on the system. (CVE-2013-1929)
A flaw was discovered in the Linux kernel's ftrace subsystem interface. A
local user could exploit this flaw to cause a denial of service (system
crash). (CVE-2013-3301)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-05-24·CVSS 4.4
CVE-2013-1929 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discover an error in the Linux kernel's credential handling
on unix sockets. A local user could exploit this flaw to gain
administrative privileges. (CVE-2013-1979)
A buffer overflow vulnerability was discovered in the Broadcom tg3 ethernet
driver for the Linux kernel. A local user could exploit this flaw to cause
a denial of service (crash the system) or potentially escalate privileges
on the system. (CVE-2013-1929)
An information leak was discovered in the Linux kernel's tkill and tgkill
system calls when used from compat processes. A local user could exploit
this flaw to examine potentially sensitive kernel memory. (CVE-2013-2141)
A flaw was discovered in the Linux kernel'
Red Hat
Kernel: tracing: NULL pointer dereference
vendor_redhat·2013-04-11·CVSS 7.2
CVE-2013-3301 [HIGH] CWE-476 Kernel: tracing: NULL pointer dereference
Kernel: tracing: NULL pointer dereference
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.
Statement: This issue does not affect the version of the kernel package as shipped with
Red Hat Enterprise Linux 5.
This issue affects the versions of Linux kernel as shipped with
Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future kernel updates
for Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2 may address this
issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2013-3301: linux - The ftrace implementation in the Linux kernel before 3.8.8 allows local users to...
vendor_debian·2013·CVSS 7.2
CVE-2013-3301 [HIGH] CVE-2013-3301: linux - The ftrace implementation in the Linux kernel before 3.8.8 allows local users to...
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.
Scope: local
bookworm: resolved (fixed in 3.8.11-1)
bullseye: resolved (fixed in 3.8.11-1)
forky: resolved (fixed in 3.8.11-1)
sid: resolved (fixed in 3.8.11-1)
trixie: resolved (fixed in 3.8.11-1)
GHSA
GHSA-c2pp-ff3q-qvxc: The ftrace implementation in the Linux kernel before 3
ghsa_unreviewed·2022-05-13
CVE-2013-3301 [HIGH] GHSA-c2pp-ff3q-qvxc: The ftrace implementation in the Linux kernel before 3
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.
OSV
CVE-2013-3301: The ftrace implementation in the Linux kernel before 3
osv·2013-04-29·CVSS 7.2
CVE-2013-3301 [HIGH] CVE-2013-3301: The ftrace implementation in the Linux kernel before 3
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.
No detection rules found.
Bugzilla
CVE-2013-3301 Kernel: tracing: NULL pointer dereference
bugzilla·2013-04-15·CVSS 7.2
CVE-2013-3301 [HIGH] CVE-2013-3301 Kernel: tracing: NULL pointer dereference
CVE-2013-3301 Kernel: tracing: NULL pointer dereference
Linux kernel built with Function Tracers(CONFIG_FUNCTION_TRACER) &
Stack Tracers(CONFIG_STACK_TRACER) support is vulnerable to a NULL pointer
deference flaw. It occurs while writing to `set_ftrace_pid' or
`set_graph_function' files used by kernel tracers.
A privileged(CAP_SYS_ADMIN) user could use this flaw to crash the system
resulting in DoS.
Upstream fix:
-> https://git.kernel.org/linus/6a76f8c0ab19f215af2a3442870eeb5f0e81998d
Discussion:
Statement:
This issue does not affect the version of the kernel package as shipped with
Red Hat Enterprise Linux 5.
This issue affects the versions of Linux kernel as shipped with
Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2. Future kernel updates
for Red Hat Enterprise Linux 6 a
arXiv
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
arxiv_fulltext·2022-09-26
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
Meghna Pancholi
[email protected]
Columbia University
Andreas D. Kellas
[email protected]
Columbia University
Vasileios P. Kemerlis
[email protected]
Brown University
Simha Sethumadhavan
[email protected]
Columbia University
## Abstract
We introduce , a novel technique for automatically learning system
call filtering policies for containerized microservices applications. At
run-time, automatically learns which system calls a program should
be allowed to invoke, while rejecting attempts to call spurious system calls.
Further, addresses many of the shortcomings of state-of-the-art
static analysis-based techniques, such as the ability to generate tight filters
for programs written in interpreted languages such as PHP, Python, and
JavaScript. has a simple and rob
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6a76f8c0ab19f215af2a3442870eeb5f0e81998dhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1051.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.8http://www.openwall.com/lists/oss-security/2013/04/15/1http://www.ubuntu.com/usn/USN-1834-1http://www.ubuntu.com/usn/USN-1835-1http://www.ubuntu.com/usn/USN-1836-1http://www.ubuntu.com/usn/USN-1838-1https://bugzilla.redhat.com/show_bug.cgi?id=952197https://github.com/torvalds/linux/commit/6a76f8c0ab19f215af2a3442870eeb5f0e81998dhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6a76f8c0ab19f215af2a3442870eeb5f0e81998dhttp://lists.opensuse.org/opensuse-security-announce/2013-09/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2013-12/msg00129.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1051.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.8.8http://www.openwall.com/lists/oss-security/2013/04/15/1http://www.ubuntu.com/usn/USN-1834-1http://www.ubuntu.com/usn/USN-1835-1http://www.ubuntu.com/usn/USN-1836-1http://www.ubuntu.com/usn/USN-1838-1https://bugzilla.redhat.com/show_bug.cgi?id=952197https://github.com/torvalds/linux/commit/6a76f8c0ab19f215af2a3442870eeb5f0e81998d
2013-04-29
Published