CVE-2013-4348
published 2013-11-04CVE-2013-4348: The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite…
PriorityP335high7.1CVSS 2.0
AVNACMAuNCNINAC
EPSS
9.41%
94.9th percentile
The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 3.11.6-2 (bookworm) | linux 3.11.6-2 (bookworm) |
| linux | linux_kernel | >= 0 < 3.11.6-2 | 3.11.6-2 |
| linux | linux_kernel | >= 0 < 3.11.6-2 | 3.11.6-2 |
| linux | linux_kernel | >= 0 < 3.11.6-2 | 3.11.6-2 |
| linux | linux_kernel | >= 0 < 3.11.6-2 | 3.11.6-2 |
| linux | linux_kernel | >= 3.11 < 3.11.9 | 3.11.9 |
| linux | linux_kernel | >= 3.12 < 3.12.1 | 3.12.1 |
| linux | linux_kernel | >= 3.2 < 3.2.54 | 3.2.54 |
| linux | linux_kernel | >= 3.3 < 3.4.70 | 3.4.70 |
| linux | linux_kernel | >= 3.5 < 3.10.20 | 3.10.20 |
CVSS provenance
nvdv2.07.1HIGHAV:N/AC:M/Au:N/C:N/I:N/A:C
osv7.1HIGH
vendor_debian7.1HIGH
vendor_redhat7.1HIGH
vendor_ubuntu3.6LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
A flaw in the handling of memory region
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsyst
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in t
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network f
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.6
CVE-2013-2930 [LOW] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
Multiple integer overflow flaws were discover
Red Hat
kernel: net: deadloop path in skb_flow_dissect()
vendor_redhat·2013-10-31·CVSS 7.1
CVE-2013-4348 [HIGH] CWE-228 kernel: net: deadloop path in skb_flow_dissect()
kernel: net: deadloop path in skb_flow_dissect()
The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation.
Statement: This issue does not affect Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6. Future Linux kernel updates for Red Hat Enterprise Linux MRG 2 might address this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4348: linux - The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel t...
vendor_debian·2013·CVSS 7.1
CVE-2013-4348 [HIGH] CVE-2013-4348: linux - The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel t...
The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation.
Scope: local
bookworm: resolved (fixed in 3.11.6-2)
bullseye: resolved (fixed in 3.11.6-2)
forky: resolved (fixed in 3.11.6-2)
sid: resolved (fixed in 3.11.6-2)
trixie: resolved (fixed in 3.11.6-2)
GHSA
GHSA-mm7v-94jm-v6mc: The skb_flow_dissect function in net/core/flow_dissector
ghsa_unreviewed·2022-05-17
CVE-2013-4348 [HIGH] GHSA-mm7v-94jm-v6mc: The skb_flow_dissect function in net/core/flow_dissector
The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation.
Kernel
Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next
kernel_security·2018-09-25·CVSS 7.1
CVE-2013-4348 [HIGH] Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next
Merge git://git.kernel.org/pub/scm/linux/kernel/git/bpf/bpf-next
Daniel Borkmann says:
pull-request: bpf-next 2018-09-25
The following pull-request contains BPF updates for your *net-next* tree.
The main changes are:
1) Allow for RX stack hardening by implementing the kernel's flow
dissector in BPF. Idea was originally presented at netconf 2017 [0].
Quote from merge commit:
[...] Because of the rigorous checks of the BPF verifier, this
provides significant security guarantees. In particular, the BPF
flow dissector cannot get inside of an infinite loop, as with
CVE-2013-4348, because BPF programs are guaranteed to terminate.
It cannot read outside of packet bounds, because all memory accesses
are checked. Also, with BPF the administrator can decide which
protocols to support, reducing
Kernel
Merge branch 'bpf-flow-dissector'
kernel_security·2018-09-14·CVSS 7.1
CVE-2013-4348 [HIGH] Merge branch 'bpf-flow-dissector'
Merge branch 'bpf-flow-dissector'
Petar Penkov says:
This patch series hardens the RX stack by allowing flow dissection in BPF,
as previously discussed [1]. Because of the rigorous checks of the BPF
verifier, this provides significant security guarantees. In particular, the
BPF flow dissector cannot get inside of an infinite loop, as with
CVE-2013-4348, because BPF programs are guaranteed to terminate. It cannot
read outside of packet bounds, because all memory accesses are checked.
Also, with BPF the administrator can decide which protocols to support,
reducing potential attack surface. Rarely encountered protocols can be
excluded from dissection and the program can be updated without kernel
recompile or reboot if a bug is discovered.
Patch 1 adds infrastructure to execute a BPF progra
OSV
CVE-2013-4348: The skb_flow_dissect function in net/core/flow_dissector
osv·2013-11-04·CVSS 7.1
CVE-2013-4348 [HIGH] CVE-2013-4348: The skb_flow_dissect function in net/core/flow_dissector
The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4348 kernel: net: deadloop path in skb_flow_dissect() [fedora-all]
bugzilla·2013-11-01·CVSS 7.1
CVE-2013-4348 [HIGH] CVE-2013-4348 kernel: net: deadloop path in skb_flow_dissect() [fedora-all]
CVE-2013-4348 kernel: net: deadloop path in skb_flow_dissect() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affec
Bugzilla
CVE-2013-4348 kernel: net: deadloop path in skb_flow_dissect()
bugzilla·2013-09-13·CVSS 7.1
CVE-2013-4348 [HIGH] CVE-2013-4348 kernel: net: deadloop path in skb_flow_dissect()
CVE-2013-4348 kernel: net: deadloop path in skb_flow_dissect()
A flaw was found in the way ip packets with ihl of zero were processed in the skb_flow_dissect() function in the Linux kernel.
A remote attacker could use this flaw to cause inifinite loop in the kernel.
Acknowledgements:
This issue was found by Jason Wang of Red Hat.
Discussion:
Statement:
This issue does not affect Linux kernel packages as shipped with Red Hat Enterprise Linux 5 and 6. Future Linux kernel updates for Red Hat Enterprise Linux MRG 2 might address this issue.
---
This issue has been addressed in following products:
MRG for RHEL-6 v.2
Via RHSA-2013:1490 https://rhn.redhat.com/errata/RHSA-2013-1490.html
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1025647]
---
http://th
http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1490.htmlhttp://www.ubuntu.com/usn/USN-2070-1http://www.ubuntu.com/usn/USN-2075-1https://bugzilla.redhat.com/show_bug.cgi?id=1007939https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=6f092343855a71e03b8d209815d8c45bf3a27fcdhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1490.htmlhttp://www.ubuntu.com/usn/USN-2070-1http://www.ubuntu.com/usn/USN-2075-1https://bugzilla.redhat.com/show_bug.cgi?id=1007939https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=6f092343855a71e03b8d209815d8c45bf3a27fcd
2013-11-04
Published