CVE-2013-4247
published 2013-08-25CVE-2013-4247: Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect.c in the Linux kernel before 3.9.6 allows remote attackers to cause a denial of…
PriorityP434high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.64%
88.5th percentile
Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect.c in the Linux kernel before 3.9.6 allows remote attackers to cause a denial of service (memory corruption and system crash) via a DFS share mount operation that triggers use of an unexpected DFS referral name length.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.9.6-1 (bookworm) | linux 3.9.6-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.9.6-1 | 3.9.6-1 |
| linux | linux_kernel | >= 0 < 3.9.6-1 | 3.9.6-1 |
| linux | linux_kernel | >= 0 < 3.9.6-1 | 3.9.6-1 |
| linux | linux_kernel | >= 0 < 3.9.6-1 | 3.9.6-1 |
| linux | linux_kernel | >= 3.8 < 3.9.6 | 3.9.6 |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-cf8v-r742-2v78: Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect
ghsa_unreviewed·2022-05-17
CVE-2013-4247 [HIGH] GHSA-cf8v-r742-2v78: Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect
Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect.c in the Linux kernel before 3.9.6 allows remote attackers to cause a denial of service (memory corruption and system crash) via a DFS share mount operation that triggers use of an unexpected DFS referral name length.
OSV
CVE-2013-4247: Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect
osv·2013-08-25·CVSS 7.8
CVE-2013-4247 [HIGH] CVE-2013-4247: Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect
Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect.c in the Linux kernel before 3.9.6 allows remote attackers to cause a denial of service (memory corruption and system crash) via a DFS share mount operation that triggers use of an unexpected DFS referral name length.
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-08-20·CVSS 7.8
CVE-2013-1059 [HIGH] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Chanam Park reported a Null pointer flaw in the Linux kernel's Ceph client.
A remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2013-1059)
An information leak was discovered in the Linux kernel's fanotify
interface. A local user could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2013-2148)
Jonathan Salwan discovered an information leak in the Linux kernel's cdrom
driver. A local user can exploit this leak to obtain sensitive information
from kernel memory if the CD-ROM drive is malfunctioning. (CVE-2013-2164)
Kees Cook discovered a format string vulnerability in the Linux kernel's
disk block layer. A local use
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2013-07-29·CVSS 6.9
CVE-2013-2852 [MEDIUM] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to crash or run programs as an administrator.
Kees Cook discovered a format string vulnerability in the Broadcom B43
wireless driver for the Linux kernel. A local user could exploit this flaw
to gain administrative privileges. (CVE-2013-2852)
Marcus Moeller and Ken Fallon discovered that the CIFS incorrectly built
certain paths. A local attacker with access to a CIFS partition could
exploit this to crash the system, leading to a denial of service.
(CVE-2013-4247)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall
Red Hat
kernel: cifs: off-by-one bug in build_unc_path_to_root
vendor_redhat·2013-05-31·CVSS 7.8
CVE-2013-4247 [HIGH] CWE-193 kernel: cifs: off-by-one bug in build_unc_path_to_root
kernel: cifs: off-by-one bug in build_unc_path_to_root
Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect.c in the Linux kernel before 3.9.6 allows remote attackers to cause a denial of service (memory corruption and system crash) via a DFS share mount operation that triggers use of an unexpected DFS referral name length.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-4247: linux - Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect.c in ...
vendor_debian·2013·CVSS 7.8
CVE-2013-4247 [HIGH] CVE-2013-4247: linux - Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect.c in ...
Off-by-one error in the build_unc_path_to_root function in fs/cifs/connect.c in the Linux kernel before 3.9.6 allows remote attackers to cause a denial of service (memory corruption and system crash) via a DFS share mount operation that triggers use of an unexpected DFS referral name length.
Scope: local
bookworm: resolved (fixed in 3.9.6-1)
bullseye: resolved (fixed in 3.9.6-1)
forky: resolved (fixed in 3.9.6-1)
sid: resolved (fixed in 3.9.6-1)
trixie: resolved (fixed in 3.9.6-1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1fc29bacedeabb278080e31bb9c1ecb49f143c3bhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.9.6http://www.openwall.com/lists/oss-security/2013/08/14/10https://bugzilla.redhat.com/show_bug.cgi?id=998401https://github.com/torvalds/linux/commit/1fc29bacedeabb278080e31bb9c1ecb49f143c3bhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1fc29bacedeabb278080e31bb9c1ecb49f143c3bhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.9.6http://www.openwall.com/lists/oss-security/2013/08/14/10https://bugzilla.redhat.com/show_bug.cgi?id=998401https://github.com/torvalds/linux/commit/1fc29bacedeabb278080e31bb9c1ecb49f143c3b
2013-08-25
Published