Public exploit available
Public proof-of-concept or exploit code exists (ExploitDB / Metasploit / Nuclei).

CVE-2013-3301

Severity
7.2HIGH
EPSS
0.4%
top 40.97%
CISA KEV
Not in KEV
Exploit
PoC available
Public exploit / PoC exists
Timeline
PublishedApr 29
Latest updateMay 13

Description

The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.

CVSS vector

AV:L/AC:L/C:C/I:C/A:CExploitability: 3.9 | Impact: 10.0

Affected Packages6 packages

Also affects: Enterprise Linux 6.0

🔴Vulnerability Details

3
GHSA
GHSA-c2pp-ff3q-qvxc: The ftrace implementation in the Linux kernel before 32022-05-13
CVEList
CVE-2013-3301: The ftrace implementation in the Linux kernel before 32013-04-29
OSV
CVE-2013-3301: The ftrace implementation in the Linux kernel before 32013-04-29

💥Exploits & PoCs

1
Exploit-DB
Linux Kernel 3.2.1 - Tracing Multiple Local Denial of Service Vulnerabilities2013-04-15

📋Vendor Advisories

7
Ubuntu
Linux kernel (OMAP4) vulnerabilities2013-05-30
Ubuntu
Linux kernel (OMAP4) vulnerabilities2013-05-28
Ubuntu
Linux kernel vulnerabilities2013-05-24
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities2013-05-24
Ubuntu
Linux kernel vulnerabilities2013-05-24

💬Community

1
Bugzilla
CVE-2013-3301 Kernel: tracing: NULL pointer dereference2013-04-15
CVE-2013-3301 (HIGH CVSS 7.2) | The ftrace implementation in the Li | cvebase.io