CVE-2013-4300
published 2013-09-25CVE-2013-4300: The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users…
PriorityP429high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.42%
34.8th percentile
The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users to gain privileges via PID spoofing.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.11.5-1 (bookworm) | linux 3.11.5-1 (bookworm) |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.11.5-1 | 3.11.5-1 |
| linux | linux_kernel | >= 0 < 3.11.5-1 | 3.11.5-1 |
| linux | linux_kernel | >= 0 < 3.11.5-1 | 3.11.5-1 |
| linux | linux_kernel | >= 0 < 3.11.5-1 | 3.11.5-1 |
| linux | linux_kernel | >= 3.8.6 < 3.9 | 3.9 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-29ch-f7xh-hrh2: The scm_check_creds function in net/core/scm
ghsa_unreviewed·2022-05-17
CVE-2013-4300 [HIGH] GHSA-29ch-f7xh-hrh2: The scm_check_creds function in net/core/scm
The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users to gain privileges via PID spoofing.
OSV
CVE-2013-4300: The scm_check_creds function in net/core/scm
osv·2013-09-25·CVSS 7.2
CVE-2013-4300 [HIGH] CVE-2013-4300: The scm_check_creds function in net/core/scm
The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users to gain privileges via PID spoofing.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2013-10-22·CVSS 2.1
CVE-2013-2237 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the Linux kernel when reading
broadcast messages from the notify_policy interface of the IPSec
key_socket. A local user could exploit this flaw to examine potentially
sensitive information in kernel memory. (CVE-2013-2237)
Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit this flaw
to execute arbitrary code or cause a denial of service (heap memory
corruption) via a specially crafted device that provides an invalid Report
ID. (CVE-2013-2888)
Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kerenl when CONFIG_HID_PANTHERLORD is ena
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2013-10-22·CVSS 2.1
CVE-2013-2237 [LOW] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the Linux kernel when reading
broadcast messages from the notify_policy interface of the IPSec
key_socket. A local user could exploit this flaw to examine potentially
sensitive information in kernel memory. (CVE-2013-2237)
Kees Cook discovered flaw in the Human Interface Device (HID) subsystem of
the Linux kernel. A physically proximate attacker could exploit this flaw
to execute arbitrary code or cause a denial of service (heap memory
corruption) via a specially crafted device that provides an invalid Report
ID. (CVE-2013-2888)
Kees Cook discovered a flaw in the Human Interface Device (HID) subsystem
of the Linux kerenl when CONFIG_HID_PANTH
Red Hat
Kernel: net: PID spoofing privilege escalation flaw
vendor_redhat·2013-08-22·CVSS 7.2
CVE-2013-4300 [HIGH] Kernel: net: PID spoofing privilege escalation flaw
Kernel: net: PID spoofing privilege escalation flaw
The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users to gain privileges via PID spoofing.
Statement: Not vulnerable.
This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2013-4300: linux - The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 p...
vendor_debian·2013·CVSS 7.2
CVE-2013-4300 [HIGH] CVE-2013-4300: linux - The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 p...
The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users to gain privileges via PID spoofing.
Scope: local
bookworm: resolved (fixed in 3.11.5-1)
bullseye: resolved (fixed in 3.11.5-1)
forky: resolved (fixed in 3.11.5-1)
sid: resolved (fixed in 3.11.5-1)
trixie: resolved (fixed in 3.11.5-1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d661684cf6820331feae71146c35da83d794467ehttp://www.openwall.com/lists/oss-security/2013/09/05/3http://www.ubuntu.com/usn/USN-1995-1http://www.ubuntu.com/usn/USN-1998-1https://bugzilla.redhat.com/show_bug.cgi?id=1004736https://github.com/torvalds/linux/commit/d661684cf6820331feae71146c35da83d794467ehttps://www.kernel.org/pub/linux/kernel/v3.x/patch-3.11.bz2http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=d661684cf6820331feae71146c35da83d794467ehttp://www.openwall.com/lists/oss-security/2013/09/05/3http://www.ubuntu.com/usn/USN-1995-1http://www.ubuntu.com/usn/USN-1998-1https://bugzilla.redhat.com/show_bug.cgi?id=1004736https://github.com/torvalds/linux/commit/d661684cf6820331feae71146c35da83d794467ehttps://www.kernel.org/pub/linux/kernel/v3.x/patch-3.11.bz2
2013-09-25
Published