CVE-2013-4205
published 2013-08-25CVE-2013-4205: Memory leak in the unshare_userns function in kernel/user_namespace.c in the Linux kernel before 3.10.6 allows local users to cause a denial of service (memory…
PriorityP413medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.45%
37.4th percentile
Memory leak in the unshare_userns function in kernel/user_namespace.c in the Linux kernel before 3.10.6 allows local users to cause a denial of service (memory consumption) via an invalid CLONE_NEWUSER unshare call.
Affected
220 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.10.7-1 (bookworm) | linux 3.10.7-1 (bookworm) |
| linux | linux_kernel | <= 3.10.5 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv4.7MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-09-27·CVSS 4.7
CVE-2013-4205 [MEDIUM] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vince Weaver discovered a flaw in the perf subsystem of the Linux kernel on
ARM platforms. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-4254)
A memory leak was discovered in the user namespace facility of the Linux
kernel. A local user could cause a denial of service (memory consumption)
via the CLONE_NEWUSER unshare call. (CVE-2013-4205)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kern
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-27·CVSS 4.7
CVE-2013-4205 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vince Weaver discovered a flaw in the perf subsystem of the Linux kernel on
ARM platforms. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-4254)
A memory leak was discovered in the user namespace facility of the Linux
kernel. A local user could cause a denial of service (memory consumption)
via the CLONE_NEWUSER unshare call. (CVE-2013-4205)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules yo
Debian
CVE-2013-4205: linux - Memory leak in the unshare_userns function in kernel/user_namespace.c in the Lin...
vendor_debian·2013·CVSS 4.7
CVE-2013-4205 [MEDIUM] CVE-2013-4205: linux - Memory leak in the unshare_userns function in kernel/user_namespace.c in the Lin...
Memory leak in the unshare_userns function in kernel/user_namespace.c in the Linux kernel before 3.10.6 allows local users to cause a denial of service (memory consumption) via an invalid CLONE_NEWUSER unshare call.
Scope: local
bookworm: resolved (fixed in 3.10.7-1)
bullseye: resolved (fixed in 3.10.7-1)
forky: resolved (fixed in 3.10.7-1)
sid: resolved (fixed in 3.10.7-1)
trixie: resolved (fixed in 3.10.7-1)
Red Hat
CVE-2013-4205: Memory leak in the unshare_userns function in kernel/user_namespace
vendor_redhat·CVSS 4.7
CVE-2013-4205 [MEDIUM] CVE-2013-4205: Memory leak in the unshare_userns function in kernel/user_namespace
Memory leak in the unshare_userns function in kernel/user_namespace.c in the Linux kernel before 3.10.6 allows local users to cause a denial of service (memory consumption) via an invalid CLONE_NEWUSER unshare call.
Statement: Not vulnerable.
This issue did not affect the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG 2.
GHSA
GHSA-66pg-hpcf-98q2: Memory leak in the unshare_userns function in kernel/user_namespace
ghsa_unreviewed·2022-05-17
CVE-2013-4205 [MEDIUM] GHSA-66pg-hpcf-98q2: Memory leak in the unshare_userns function in kernel/user_namespace
Memory leak in the unshare_userns function in kernel/user_namespace.c in the Linux kernel before 3.10.6 allows local users to cause a denial of service (memory consumption) via an invalid CLONE_NEWUSER unshare call.
OSV
CVE-2013-4205: Memory leak in the unshare_userns function in kernel/user_namespace
osv·2013-08-25·CVSS 4.7
CVE-2013-4205 [MEDIUM] CVE-2013-4205: Memory leak in the unshare_userns function in kernel/user_namespace
Memory leak in the unshare_userns function in kernel/user_namespace.c in the Linux kernel before 3.10.6 allows local users to cause a denial of service (memory consumption) via an invalid CLONE_NEWUSER unshare call.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6160968cee8b90a5dd95318d716e31d7775c4ef3http://twitter.com/grsecurity/statuses/364566062336978944http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.6http://www.openwall.com/lists/oss-security/2013/08/06/2http://www.ubuntu.com/usn/USN-1971-1http://www.ubuntu.com/usn/USN-1974-1https://github.com/torvalds/linux/commit/6160968cee8b90a5dd95318d716e31d7775c4ef3http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6160968cee8b90a5dd95318d716e31d7775c4ef3http://twitter.com/grsecurity/statuses/364566062336978944http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.6http://www.openwall.com/lists/oss-security/2013/08/06/2http://www.ubuntu.com/usn/USN-1971-1http://www.ubuntu.com/usn/USN-1974-1https://github.com/torvalds/linux/commit/6160968cee8b90a5dd95318d716e31d7775c4ef3
2013-08-25
Published