CVE-2013-4127
published 2013-07-29CVE-2013-4127: Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vhost/net.c in the Linux kernel through 3.10.3 allows local users to cause a…
PriorityP415medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.45%
37.3th percentile
Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vhost/net.c in the Linux kernel through 3.10.3 allows local users to cause a denial of service (OOPS and system crash) via vectors involving powering on a virtual machine.
Affected
217 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.10.5-1 (bookworm) | linux 3.10.5-1 (bookworm) |
| linux | linux_kernel | <= 3.10.3 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_ubuntu7.8HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cchm-m9vf-fxr7: Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vhost/net
ghsa_unreviewed·2022-05-17
CVE-2013-4127 [MEDIUM] GHSA-cchm-m9vf-fxr7: Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vhost/net
Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vhost/net.c in the Linux kernel through 3.10.3 allows local users to cause a denial of service (OOPS and system crash) via vectors involving powering on a virtual machine.
OSV
CVE-2013-4127: Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vhost/net
osv·2013-07-29·CVSS 4.7
CVE-2013-4127 [MEDIUM] CVE-2013-4127: Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vhost/net
Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vhost/net.c in the Linux kernel through 3.10.3 allows local users to cause a denial of service (OOPS and system crash) via vectors involving powering on a virtual machine.
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local use
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local user with admini
Red Hat
kernel: vhost-net: use-after-free in vhost_net_flush
vendor_redhat·2013-07-03·CVSS 4.7
CVE-2013-4127 [MEDIUM] CWE-416 kernel: vhost-net: use-after-free in vhost_net_flush
kernel: vhost-net: use-after-free in vhost_net_flush
Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vhost/net.c in the Linux kernel through 3.10.3 allows local users to cause a denial of service (OOPS and system crash) via vectors involving powering on a virtual machine.
Statement: Not vulnerable.
This issue did not affect the kernel packages as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-4127: linux - Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vh...
vendor_debian·2013·CVSS 4.7
CVE-2013-4127 [MEDIUM] CVE-2013-4127: linux - Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vh...
Use-after-free vulnerability in the vhost_net_set_backend function in drivers/vhost/net.c in the Linux kernel through 3.10.3 allows local users to cause a denial of service (OOPS and system crash) via vectors involving powering on a virtual machine.
Scope: local
bookworm: resolved (fixed in 3.10.5-1)
bullseye: resolved (fixed in 3.10.5-1)
forky: resolved (fixed in 3.10.5-1)
sid: resolved (fixed in 3.10.5-1)
trixie: resolved (fixed in 3.10.5-1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=dd7633ecd553a5e304d349aa6f8eb8a0417098c5http://www.openwall.com/lists/oss-security/2013/07/15/7https://bugzilla.redhat.com/show_bug.cgi?id=980643https://bugzilla.redhat.com/show_bug.cgi?id=984722https://github.com/torvalds/linux/commit/dd7633ecd553a5e304d349aa6f8eb8a0417098c5http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=dd7633ecd553a5e304d349aa6f8eb8a0417098c5http://www.openwall.com/lists/oss-security/2013/07/15/7https://bugzilla.redhat.com/show_bug.cgi?id=980643https://bugzilla.redhat.com/show_bug.cgi?id=984722https://github.com/torvalds/linux/commit/dd7633ecd553a5e304d349aa6f8eb8a0417098c5
2013-07-29
Published