CVE-2013-4254
published 2013-08-25CVE-2013-4254: The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or…
PriorityP420medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.43%
35.0th percentile
The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by adding a hardware event to an event group led by a software event.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.10.11-1 (bookworm) | linux 3.10.11-1 (bookworm) |
| linux | linux_kernel | <= 3.10.7 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.10.11-1 | 3.10.11-1 |
| linux | linux_kernel | >= 0 < 3.10.11-1 | 3.10.11-1 |
| linux | linux_kernel | >= 0 < 3.10.11-1 | 3.10.11-1 |
| linux | linux_kernel | >= 0 < 3.10.11-1 | 3.10.11-1 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-27·CVSS 4.6
CVE-2013-1819 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vince Weaver discovered a flaw in the perf subsystem of the Linux kernel on
ARM platforms. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-4254)
A failure to validate block numbers was discovered in the Linux kernel's
implementation of the XFS filesystem. A local user can cause a denial of
service (system crash) if they can mount, or cause to be mounted a
corrupted or special crafted XFS filesystem. (CVE-2013-1819)
An information leak was discovered in the Linux kernel when reading
broadcast messages from the notify_policy interface of the IPSec
key_socket. A local user could exploit this flaw to examine potentially
sensitive info
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-09-27·CVSS 4.7
CVE-2013-4205 [MEDIUM] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vince Weaver discovered a flaw in the perf subsystem of the Linux kernel on
ARM platforms. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-4254)
A memory leak was discovered in the user namespace facility of the Linux
kernel. A local user could cause a denial of service (memory consumption)
via the CLONE_NEWUSER unshare call. (CVE-2013-4205)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kern
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2013-09-27·CVSS 4.6
CVE-2013-1819 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vince Weaver discovered a flaw in the perf subsystem of the Linux kernel on
ARM platforms. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-4254)
A failure to validate block numbers was discovered in the Linux kernel's
implementation of the XFS filesystem. A local user can cause a denial of
service (system crash) if they can mount, or cause to be mounted a
corrupted or special crafted XFS filesystem. (CVE-2013-1819)
An information leak was discovered in the Linux kernel when reading
broadcast messages from the notify_policy interface of the IPSec
key_socket. A local user could exploit this flaw to examine potentially
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-09-27·CVSS 4.6
CVE-2013-1819 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vince Weaver discovered a flaw in the perf subsystem of the Linux kernel on
ARM platforms. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-4254)
A failure to validate block numbers was discovered in the Linux kernel's
implementation of the XFS filesystem. A local user can cause a denial of
service (system crash) if they can mount, or cause to be mounted a
corrupted or special crafted XFS filesystem. (CVE-2013-1819)
An information leak was discovered in the Linux kernel when reading
broadcast messages from the notify_policy interface of the IPSec
key_socket. A local user could exploit this flaw to examine potentially
sensit
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-27·CVSS 4.7
CVE-2013-4205 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vince Weaver discovered a flaw in the perf subsystem of the Linux kernel on
ARM platforms. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-4254)
A memory leak was discovered in the user namespace facility of the Linux
kernel. A local user could cause a denial of service (memory consumption)
via the CLONE_NEWUSER unshare call. (CVE-2013-4205)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel modules yo
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2013-09-27·CVSS 4.6
CVE-2013-1819 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vince Weaver discovered a flaw in the perf subsystem of the Linux kernel on
ARM platforms. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-4254)
A failure to validate block numbers was discovered in the Linux kernel's
implementation of the XFS filesystem. A local user can cause a denial of
service (system crash) if they can mount, or cause to be mounted a
corrupted or special crafted XFS filesystem. (CVE-2013-1819)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version numb
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-09-27·CVSS 4.6
CVE-2013-1819 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vince Weaver discovered a flaw in the perf subsystem of the Linux kernel on
ARM platforms. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-4254)
A failure to validate block numbers was discovered in the Linux kernel's
implementation of the XFS filesystem. A local user can cause a denial of
service (system crash) if they can mount, or cause to be mounted a
corrupted or special crafted XFS filesystem. (CVE-2013-1819)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, whic
Red Hat
Kernel: ARM: perf: NULL pointer dereference in validate_event
vendor_redhat·2013-08-05·CVSS 6.9
CVE-2013-4254 [MEDIUM] CWE-476 Kernel: ARM: perf: NULL pointer dereference in validate_event
Kernel: ARM: perf: NULL pointer dereference in validate_event
The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by adding a hardware event to an event group led by a software event.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-4254: linux - The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel ...
vendor_debian·2013·CVSS 6.9
CVE-2013-4254 [MEDIUM] CVE-2013-4254: linux - The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel ...
The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by adding a hardware event to an event group led by a software event.
Scope: local
bookworm: resolved (fixed in 3.10.11-1)
bullseye: resolved (fixed in 3.10.11-1)
forky: resolved (fixed in 3.10.11-1)
sid: resolved (fixed in 3.10.11-1)
trixie: resolved (fixed in 3.10.11-1)
GHSA
GHSA-4w76-hr8w-36w7: The validate_event function in arch/arm/kernel/perf_event
ghsa_unreviewed·2022-05-17
CVE-2013-4254 [MEDIUM] CWE-20 GHSA-4w76-hr8w-36w7: The validate_event function in arch/arm/kernel/perf_event
The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by adding a hardware event to an event group led by a software event.
OSV
CVE-2013-4254: The validate_event function in arch/arm/kernel/perf_event
osv·2013-08-25·CVSS 6.9
CVE-2013-4254 [MEDIUM] CVE-2013-4254: The validate_event function in arch/arm/kernel/perf_event
The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by adding a hardware event to an event group led by a software event.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4254 Kernel: ARM: perf: NULL pointer dereference in validate_event
bugzilla·2013-08-20·CVSS 6.9
CVE-2013-4254 [MEDIUM] CVE-2013-4254 Kernel: ARM: perf: NULL pointer dereference in validate_event
CVE-2013-4254 Kernel: ARM: perf: NULL pointer dereference in validate_event
Linux kernel built for the ARM(CONFIG_ARM/CONFIG_ARM64) platforms along with the
hardware performance counter support(CONFIG_HW_PERF_EVENTS) is vulnerable to a
NULL pointer dereference flaw. This could lead to the kernel crash resulting in
DoS or potential privilege escalation to gain root privileges by a non-root user.
An unprivileged user/program could use this flaw to crash the kernel resulting
in DoS or potential privilege escalation to gain root access to a machine.
Upstream fix:
-> https://lkml.org/lkml/2013/8/7/259
Reference:
-> http://seclists.org/oss-sec/2013/q3/381
Discussion:
Statement:
This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6 and
Bugzilla
CVE-2013-4254 Kernel: ARM: perf: NULL pointer dereference in validate_event [fedora-all]
bugzilla·2013-08-20·CVSS 6.9
CVE-2013-4254 [MEDIUM] CVE-2013-4254 Kernel: ARM: perf: NULL pointer dereference in validate_event [fedora-all]
CVE-2013-4254 Kernel: ARM: perf: NULL pointer dereference in validate_event [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c95eb3184ea1a3a2551df57190c81da695e2144bhttp://secunia.com/advisories/54494http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.8http://www.openwall.com/lists/oss-security/2013/08/16/6http://www.ubuntu.com/usn/USN-1968-1http://www.ubuntu.com/usn/USN-1969-1http://www.ubuntu.com/usn/USN-1970-1http://www.ubuntu.com/usn/USN-1971-1http://www.ubuntu.com/usn/USN-1972-1http://www.ubuntu.com/usn/USN-1973-1http://www.ubuntu.com/usn/USN-1974-1http://www.ubuntu.com/usn/USN-1975-1https://bugzilla.redhat.com/show_bug.cgi?id=998878https://github.com/torvalds/linux/commit/c95eb3184ea1a3a2551df57190c81da695e2144bhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c95eb3184ea1a3a2551df57190c81da695e2144bhttp://secunia.com/advisories/54494http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.8http://www.openwall.com/lists/oss-security/2013/08/16/6http://www.ubuntu.com/usn/USN-1968-1http://www.ubuntu.com/usn/USN-1969-1http://www.ubuntu.com/usn/USN-1970-1http://www.ubuntu.com/usn/USN-1971-1http://www.ubuntu.com/usn/USN-1972-1http://www.ubuntu.com/usn/USN-1973-1http://www.ubuntu.com/usn/USN-1974-1http://www.ubuntu.com/usn/USN-1975-1https://bugzilla.redhat.com/show_bug.cgi?id=998878https://github.com/torvalds/linux/commit/c95eb3184ea1a3a2551df57190c81da695e2144b
2013-08-25
Published