CVE-2013-4591
published 2013-11-20CVE-2013-4591: Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service…
PriorityP421medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.57%
43.8th percentile
Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a getxattr system call for the system.nfs4_acl extended attribute of a pathname on an NFSv4 filesystem.
Affected
179 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.8-1 (bookworm) | linux 3.8-1 (bookworm) |
| linux | linux_kernel | <= 3.7.1 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-5222-p8x3-g8gv: Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc
ghsa_unreviewed·2022-05-17
CVE-2013-4591 [MEDIUM] CWE-119 GHSA-5222-p8x3-g8gv: Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc
Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a getxattr system call for the system.nfs4_acl extended attribute of a pathname on an NFSv4 filesystem.
OSV
CVE-2013-4591: Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc
osv·2013-11-20·CVSS 6.2
CVE-2013-4591 [MEDIUM] CVE-2013-4591: Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc
Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a getxattr system call for the system.nfs4_acl extended attribute of a pathname on an NFSv4 filesystem.
Debian
CVE-2013-4591: linux - Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in ...
vendor_debian·2013·CVSS 6.2
CVE-2013-4591 [MEDIUM] CVE-2013-4591: linux - Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in ...
Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a getxattr system call for the system.nfs4_acl extended attribute of a pathname on an NFSv4 filesystem.
Scope: local
bookworm: resolved (fixed in 3.8-1)
bullseye: resolved (fixed in 3.8-1)
forky: resolved (fixed in 3.8-1)
sid: resolved (fixed in 3.8-1)
trixie: resolved (fixed in 3.8-1)
Red Hat
kernel: nfs: missing check for buffer length in __nfs4_get_acl_uncached
vendor_redhat·2012-12-11·CVSS 6.2
CVE-2013-4591 [MEDIUM] kernel: nfs: missing check for buffer length in __nfs4_get_acl_uncached
kernel: nfs: missing check for buffer length in __nfs4_get_acl_uncached
Buffer overflow in the __nfs4_get_acl_uncached function in fs/nfs/nfs4proc.c in the Linux kernel before 3.7.2 allows local users to cause a denial of service (memory corruption and system crash) or possibly have unspecified other impact via a getxattr system call for the system.nfs4_acl extended attribute of a pathname on an NFSv4 filesystem.
Statement: This issue did not affect the version of Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7d3e91a89b7adbc2831334def9e494dd9892f9afhttp://rhn.redhat.com/errata/RHSA-2013-1645.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0284.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.2http://www.openwall.com/lists/oss-security/2013/11/18/2http://www.securityfocus.com/bid/63791https://bugzilla.redhat.com/show_bug.cgi?id=1031678https://github.com/torvalds/linux/commit/7d3e91a89b7adbc2831334def9e494dd9892f9afhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=7d3e91a89b7adbc2831334def9e494dd9892f9afhttp://rhn.redhat.com/errata/RHSA-2013-1645.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0284.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.7.2http://www.openwall.com/lists/oss-security/2013/11/18/2http://www.securityfocus.com/bid/63791https://bugzilla.redhat.com/show_bug.cgi?id=1031678https://github.com/torvalds/linux/commit/7d3e91a89b7adbc2831334def9e494dd9892f9af
2013-11-20
Published