cbcvebase.
CVE-2013-4343
published 2013-09-25

CVE-2013-4343: Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN…

PriorityP425medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.36%
28.3th percentile
Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN capability and providing an invalid tuntap interface name in a TUNSETIFF ioctl call.

Affected

15 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 3.11.5-1 (bookworm)linux 3.11.5-1 (bookworm)
debianlinux< linux 4.14.2-1 (bookworm)linux 4.14.2-1 (bookworm)
linuxlinux_kernel< 4.13.144.13.14
linuxlinux_kernel>= 0 < 3.11.5-13.11.5-1
linuxlinux_kernel>= 0 < 4.14.2-14.14.2-1
linuxlinux_kernel>= 0 < 3.11.5-13.11.5-1
linuxlinux_kernel>= 0 < 4.14.2-14.14.2-1
linuxlinux_kernel>= 0 < 3.11.5-13.11.5-1
linuxlinux_kernel>= 0 < 4.14.2-14.14.2-1
linuxlinux_kernel>= 0 < 3.11.5-13.11.5-1
linuxlinux_kernel>= 0 < 4.14.2-14.14.2-1
linuxlinux_kernel>= 3.11 < 3.11.53.11.5
linuxlinux_kernel>= 3.8 < 3.10.163.10.16

CVSS provenance

nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.