CVE-2013-4483
published 2013-11-04CVE-2013-4483: The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does not properly manage a reference count, which allows local users to cause a…
PriorityP414medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.49%
39.8th percentile
The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does not properly manage a reference count, which allows local users to cause a denial of service (memory consumption or system crash) via a crafted application.
Affected
215 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.11.8-1 (bookworm) | linux 3.11.8-1 (bookworm) |
| linux | linux_kernel | <= 3.9.11 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_ubuntu6.1MEDIUM
vendor_debian4.9LOW
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 6.1
CVE-2013-4387 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
Dmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP
Fragmentation Offload (UFO) processing. A remote attacker could leverage
this flaw to cause a denial of service (system crash). (CVE-2013-4387)
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
A flaw was discovere
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 4.9
CVE-2013-4483 [MEDIUM] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
A flaw was discovered in the Linux kernel's IPC reference counting. An
unprivileged local user could exploit this flaw to cause a denial of
service (OOM system crash). (CVE-2013-4483)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party kernel module
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 6.1
CVE-2013-4387 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
Dmitry Vyukov reported a flaw in the Linux kernel's handling of IPv6 UDP
Fragmentation Offload (UFO) processing. A remote attacker could leverage
this flaw to cause a denial of service (system crash). (CVE-2013-4387)
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
A flaw was dis
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-05-27·CVSS 4.9
CVE-2013-4483 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's pseudo tty (pty) device. An
unprivileged user could exploit this flaw to cause a denial of service
(system crash) or potentially gain administrator privileges.
(CVE-2014-0196)
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in the handling of ioctl commands by the
floppy disk driver in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges if the floppy disk
module is loaded. (CVE-2014-1737)
A
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2014-05-27·CVSS 4.9
CVE-2013-4483 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in the handling of ioctl commands by the
floppy disk driver in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges if the floppy disk
module is loaded. (CVE-2014-1737)
A flaw was discovered in the Linux kernel's IPC reference counting. An
unprivileged local user could exploit this flaw to cause a denial of
service (OOM system crash). (CVE-2013-4483)
A flaw was discovered in the vho
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-05-26·CVSS 4.9
CVE-2013-4483 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in the handling of ioctl commands by the
floppy disk driver in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges if the floppy disk
module is loaded. (CVE-2014-1737)
A flaw was discovered in the Linux kernel's IPC reference counting. An
unprivileged local user could exploit this flaw to cause a denial of
service (OOM system crash). (CVE-2013-4483)
Al Viro discovered an error in how CIFS in the
Red Hat
kernel: ipc: ipc_rcu_putref refcount races
vendor_redhat·2013-10-29·CVSS 4.9
CVE-2013-4483 [MEDIUM] kernel: ipc: ipc_rcu_putref refcount races
kernel: ipc: ipc_rcu_putref refcount races
The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does not properly manage a reference count, which allows local users to cause a denial of service (memory consumption or system crash) via a crafted application.
A flaw was found in the way the ipc_rcu_putref() function in the Linux kernel's IPC implementation handled reference counter decrementing. A local, unprivileged user could use this flaw to trigger an Out of Memory (OOM) condition and, potentially, crash the system.
Statement: This issue does affect Linux kernel packages as shipped with Red Hat Enterprise Linux 6. Future kernel updates for respective releases may address this issue.
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-4483: linux - The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does n...
vendor_debian·2013·CVSS 4.9
CVE-2013-4483 [MEDIUM] CVE-2013-4483: linux - The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does n...
The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does not properly manage a reference count, which allows local users to cause a denial of service (memory consumption or system crash) via a crafted application.
Scope: local
bookworm: resolved (fixed in 3.11.8-1)
bullseye: resolved (fixed in 3.11.8-1)
forky: resolved (fixed in 3.11.8-1)
sid: resolved (fixed in 3.11.8-1)
trixie: resolved (fixed in 3.11.8-1)
GHSA
GHSA-6g7q-qqm3-vgfm: The ipc_rcu_putref function in ipc/util
ghsa_unreviewed·2022-05-17
CVE-2013-4483 [MEDIUM] GHSA-6g7q-qqm3-vgfm: The ipc_rcu_putref function in ipc/util
The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does not properly manage a reference count, which allows local users to cause a denial of service (memory consumption or system crash) via a crafted application.
OSV
CVE-2013-4483: The ipc_rcu_putref function in ipc/util
osv·2013-11-04·CVSS 4.9
CVE-2013-4483 [MEDIUM] CVE-2013-4483: The ipc_rcu_putref function in ipc/util
The ipc_rcu_putref function in ipc/util.c in the Linux kernel before 3.10 does not properly manage a reference count, which allows local users to cause a denial of service (memory consumption or system crash) via a crafted application.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6062a8dc0517bce23e3c2f7d2fea5e22411269a3http://lists.opensuse.org/opensuse-updates/2014-02/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0285.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0284.htmlhttp://www.openwall.com/lists/oss-security/2013/10/30/4https://bugzilla.redhat.com/show_bug.cgi?id=1024854https://github.com/torvalds/linux/commit/6062a8dc0517bce23e3c2f7d2fea5e22411269a3https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.10.bz2http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6062a8dc0517bce23e3c2f7d2fea5e22411269a3http://lists.opensuse.org/opensuse-updates/2014-02/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0285.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0284.htmlhttp://www.openwall.com/lists/oss-security/2013/10/30/4https://bugzilla.redhat.com/show_bug.cgi?id=1024854https://github.com/torvalds/linux/commit/6062a8dc0517bce23e3c2f7d2fea5e22411269a3https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.10.bz2
2013-11-04
Published