CVE-2013-4587
published 2013-12-14CVE-2013-4587: Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to…
PriorityP429high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.53%
41.9th percentile
Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.12.5-1 (bookworm) | linux 3.12.5-1 (bookworm) |
| linux | linux_kernel | < 3.2.54 | 3.2.54 |
| linux | linux_kernel | >= 0 < 3.12.5-1 | 3.12.5-1 |
| linux | linux_kernel | >= 0 < 3.12.5-1 | 3.12.5-1 |
| linux | linux_kernel | >= 0 < 3.12.5-1 | 3.12.5-1 |
| linux | linux_kernel | >= 0 < 3.12.5-1 | 3.12.5-1 |
| linux | linux_kernel | >= 3.11 < 3.12.6 | 3.12.6 |
| linux | linux_kernel | >= 3.3 < 3.4.75 | 3.4.75 |
| linux | linux_kernel | >= 3.5 < 3.10.25 | 3.10.25 |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
| opensuse | opensuse | — | — |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
vendor_ubuntu7.1HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-03-07·CVSS 4.3
CVE-2013-4579 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Kernel
Virtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service or host OS system crash.
(CVE-2013-6367)
Andrew Honig
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-03-07·CVSS 4.3
CVE-2013-4579 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Kernel
Virtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service or host OS system crash.
(CVE-2013-6367)
Andrew Honig
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-03-07·CVSS 4.3
CVE-2013-4579 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Kernel
Virtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service or host OS system crash.
(CVE-2013-6367)
Andrew Honig reporte
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2014-03-07·CVSS 4.3
CVE-2013-4579 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Kernel
Virtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service or host OS system crash.
(CVE-2013-6367)
Andrew
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2014-03-07·CVSS 4.3
CVE-2013-4579 [MEDIUM] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Kernel
Virtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service or host OS system crash.
(CVE-2013-6367)
Andrew
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-03-06·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-03-05·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig repo
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 7.1
CVE-2013-4563 [HIGH] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Saran Neti reported a flaw in the ipv6 UDP Fragmentation Offload (UFI) in
the Linux kernel. A remote attacker could exploit this flaw to cause a
denial of service (panic). (CVE-2013-4563)
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct functi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 7.1
CVE-2013-4563 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Saran Neti reported a flaw in the ipv6 UDP Fragmentation Offload (UFI) in
the Linux kernel. A remote attacker could exploit this flaw to cause a
denial of service (panic). (CVE-2013-4563)
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Ke
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsyst
Red Hat
kernel: kvm: rtc_status.dest_map out-of-bounds access
vendor_redhat·2013-12-12·CVSS 7.2
CVE-2013-4587 [HIGH] kernel: kvm: rtc_status.dest_map out-of-bounds access
kernel: kvm: rtc_status.dest_map out-of-bounds access
Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.
Statement: Not vulnerable.
This issue did not affect the versions of kvm packages as shipped with Red Hat Enterprise Linux 5. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise 6.
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise MRG 2 as they did not provide support for the KVM subsystem.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kvm (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affec
Debian
CVE-2013-4587: linux - Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main....
vendor_debian·2013·CVSS 7.2
CVE-2013-4587 [HIGH] CVE-2013-4587: linux - Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main....
Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.
Scope: local
bookworm: resolved (fixed in 3.12.5-1)
bullseye: resolved (fixed in 3.12.5-1)
forky: resolved (fixed in 3.12.5-1)
sid: resolved (fixed in 3.12.5-1)
trixie: resolved (fixed in 3.12.5-1)
GHSA
GHSA-mc94-pmmg-x3r2: Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main
ghsa_unreviewed·2022-05-17
CVE-2013-4587 [HIGH] CWE-20 GHSA-mc94-pmmg-x3r2: Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main
Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.
OSV
CVE-2013-4587: Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main
osv·2013-12-14·CVSS 7.2
CVE-2013-4587 [HIGH] CVE-2013-4587: Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main
Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.
Kernel
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
kernel_security·2013-12-12·CVSS 7.2
CVE-2013-4587 [HIGH] Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
Merge tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm
Pull kvm fixes from Paolo Bonzini:
"Four security fixes for KVM on x86. Thanks to Andrew Honig and Lars
Bull from Google for reporting them"
* tag 'for-linus' of git://git.kernel.org/pub/scm/virt/kvm/kvm:
KVM: x86: fix guest-initiated crash with x2apic (CVE-2013-6376)
KVM: x86: Convert vapic synchronization to _cached functions (CVE-2013-6368)
KVM: x86: Fix potential divide by 0 in lapic (CVE-2013-6367)
KVM: Improve create VCPU parameter (CVE-2013-4587)
Kernel
KVM: Improve create VCPU parameter (CVE-2013-4587)
kernel_security·2013-11-18·CVSS 7.2
CVE-2013-4587 [HIGH] KVM: Improve create VCPU parameter (CVE-2013-4587)
KVM: Improve create VCPU parameter (CVE-2013-4587)
In multiple functions the vcpu_id is used as an offset into a bitfield. Ag
malicious user could specify a vcpu_id greater than 255 in order to set or
clear bits in kernel memory. This could be used to elevate priveges in the
kernel. This patch verifies that the vcpu_id provided is less than 255.
The api documentation already specifies that the vcpu_id must be less than
max_vcpus, but this is currently not checked.
Reported-by: Andrew Honig
Cc: [email protected]
Signed-off-by: Andrew Honig
Signed-off-by: Paolo Bonzini
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-4587 kernel: kvm: rtc_status.dest_map out-of-bounds access [fedora-all]
bugzilla·2013-12-12·CVSS 7.2
CVE-2013-4587 [HIGH] CVE-2013-4587 kernel: kvm: rtc_status.dest_map out-of-bounds access [fedora-all]
CVE-2013-4587 kernel: kvm: rtc_status.dest_map out-of-bounds access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
Bugzilla
CVE-2013-4587 kernel: kvm: rtc_status.dest_map out-of-bounds access
bugzilla·2013-11-15·CVSS 7.2
CVE-2013-4587 [HIGH] CVE-2013-4587 kernel: kvm: rtc_status.dest_map out-of-bounds access
CVE-2013-4587 kernel: kvm: rtc_status.dest_map out-of-bounds access
In several functions vcpu_id is used as an offset into rtc_status.dest_map in order to set or clear bits in kernel memory, potentially leading to out-of-bound access when vcpu_id is larger than 255.
An unprivileged local user could use this flaw to elevate their privileges on the system.
Acknowledgements:
Red Hat would like to thank Andrew Honig of Google for reporting this issue.
Discussion:
Statement:
Not vulnerable.
This issue did not affect the versions of kvm packages as shipped with Red Hat Enterprise Linux 5. This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise 6.
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise MRG 2 as they did
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=338c7dbadd2671189cec7faf64c84d01071b3f96http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00045.htmlhttp://www.openwall.com/lists/oss-security/2013/12/12/12http://www.ubuntu.com/usn/USN-2109-1http://www.ubuntu.com/usn/USN-2110-1http://www.ubuntu.com/usn/USN-2113-1http://www.ubuntu.com/usn/USN-2117-1http://www.ubuntu.com/usn/USN-2128-1http://www.ubuntu.com/usn/USN-2129-1http://www.ubuntu.com/usn/USN-2135-1http://www.ubuntu.com/usn/USN-2136-1http://www.ubuntu.com/usn/USN-2138-1http://www.ubuntu.com/usn/USN-2139-1http://www.ubuntu.com/usn/USN-2141-1https://bugzilla.redhat.com/show_bug.cgi?id=1030986https://github.com/torvalds/linux/commit/338c7dbadd2671189cec7faf64c84d01071b3f96https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.54http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=338c7dbadd2671189cec7faf64c84d01071b3f96http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00045.htmlhttp://www.openwall.com/lists/oss-security/2013/12/12/12http://www.ubuntu.com/usn/USN-2109-1http://www.ubuntu.com/usn/USN-2110-1http://www.ubuntu.com/usn/USN-2113-1http://www.ubuntu.com/usn/USN-2117-1http://www.ubuntu.com/usn/USN-2128-1http://www.ubuntu.com/usn/USN-2129-1http://www.ubuntu.com/usn/USN-2135-1http://www.ubuntu.com/usn/USN-2136-1http://www.ubuntu.com/usn/USN-2138-1http://www.ubuntu.com/usn/USN-2139-1http://www.ubuntu.com/usn/USN-2141-1https://bugzilla.redhat.com/show_bug.cgi?id=1030986https://github.com/torvalds/linux/commit/338c7dbadd2671189cec7faf64c84d01071b3f96https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.54
2013-12-14
Published