CVE-2013-4592
published 2013-11-20CVE-2013-4592: Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main.c in the Linux kernel before 3.9 allows local users to cause a denial of service…
PriorityP413medium4CVSS 2.0
AVLACHAuNCNINAC
EPSS
0.50%
40.4th percentile
Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main.c in the Linux kernel before 3.9 allows local users to cause a denial of service (memory consumption) by leveraging certain device access to trigger movement of memory slots.
Affected
204 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.8-1 (bookworm) | linux 3.8-1 (bookworm) |
| linux | linux_kernel | <= 3.9 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:L/AC:H/Au:N/C:N/I:N/A:C
osv4.0MEDIUM
vendor_ubuntu6.0MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
A flaw in the handling of memory regions of the kernel virtual machine
(KVM) subsystem was discovered. A local user with the ability to assign a
device could exploit this flaw to cause a denial of service (memory
consumption). (CVE-2013-4592)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde and Fabian Yamaguchi reported a flaw in the
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
A flaw in the handling of memory regions of the kernel virtual machine
(KVM) subsystem was discovered. A local user with the ability to assign a
device could exploit this flaw to cause a denial of service (memory
consumption). (CVE-2013-4592)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde and Fabian Yamaguchi reported a flaw i
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
A flaw in the handling of memory region
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
A flaw in the handling of memory regions of the kernel virtual machine
(KVM) subsystem was discovered. A local user with the ability to assign a
device could exploit this flaw to cause a denial of service (memory
consumption). (CVE-2013-4592)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde and Fabian Yamaguchi reported a flaw in the driver f
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 6.0
CVE-2013-4299 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 6.0
CVE-2013-4299 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a flaw i
Debian
CVE-2013-4592: linux - Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main.c in th...
vendor_debian·2013·CVSS 4.0
CVE-2013-4592 [MEDIUM] CVE-2013-4592: linux - Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main.c in th...
Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main.c in the Linux kernel before 3.9 allows local users to cause a denial of service (memory consumption) by leveraging certain device access to trigger movement of memory slots.
Scope: local
bookworm: resolved (fixed in 3.8-1)
bullseye: resolved (fixed in 3.8-1)
forky: resolved (fixed in 3.8-1)
sid: resolved (fixed in 3.8-1)
trixie: resolved (fixed in 3.8-1)
Red Hat
kernel: kvm: memory leak when memory slot is moved with assigned device
vendor_redhat·2012-12-10·CVSS 4.0
CVE-2013-4592 [MEDIUM] CWE-401 kernel: kvm: memory leak when memory slot is moved with assigned device
kernel: kvm: memory leak when memory slot is moved with assigned device
Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main.c in the Linux kernel before 3.9 allows local users to cause a denial of service (memory consumption) by leveraging certain device access to trigger movement of memory slots.
Package: kvm (Red Hat Enterprise Linux 5) - Will not fix
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
GHSA
GHSA-v9q2-89fg-9h45: Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main
ghsa_unreviewed·2022-05-17
CVE-2013-4592 [MEDIUM] GHSA-v9q2-89fg-9h45: Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main
Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main.c in the Linux kernel before 3.9 allows local users to cause a denial of service (memory consumption) by leveraging certain device access to trigger movement of memory slots.
OSV
CVE-2013-4592: Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main
osv·2013-11-20·CVSS 4.0
CVE-2013-4592 [MEDIUM] CVE-2013-4592: Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main
Memory leak in the __kvm_set_memory_region function in virt/kvm/kvm_main.c in the Linux kernel before 3.9 allows local users to cause a denial of service (memory consumption) by leveraging certain device access to trigger movement of memory slots.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=12d6e7538e2d418c08f082b1b44ffa5fb7270ed8http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e40f193f5bb022e927a57a4f5d5194e4f12ddb74http://lists.opensuse.org/opensuse-updates/2014-02/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1645.htmlhttp://www.openwall.com/lists/oss-security/2013/11/18/3http://www.ubuntu.com/usn/USN-2066-1http://www.ubuntu.com/usn/USN-2067-1http://www.ubuntu.com/usn/USN-2111-1http://www.ubuntu.com/usn/USN-2112-1http://www.ubuntu.com/usn/USN-2114-1http://www.ubuntu.com/usn/USN-2115-1http://www.ubuntu.com/usn/USN-2116-1https://bugzilla.redhat.com/show_bug.cgi?id=1031702https://github.com/torvalds/linux/commit/12d6e7538e2d418c08f082b1b44ffa5fb7270ed8https://github.com/torvalds/linux/commit/e40f193f5bb022e927a57a4f5d5194e4f12ddb74https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.9.bz2http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=12d6e7538e2d418c08f082b1b44ffa5fb7270ed8http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e40f193f5bb022e927a57a4f5d5194e4f12ddb74http://lists.opensuse.org/opensuse-updates/2014-02/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2013-1645.htmlhttp://www.openwall.com/lists/oss-security/2013/11/18/3http://www.ubuntu.com/usn/USN-2066-1http://www.ubuntu.com/usn/USN-2067-1http://www.ubuntu.com/usn/USN-2111-1http://www.ubuntu.com/usn/USN-2112-1http://www.ubuntu.com/usn/USN-2114-1http://www.ubuntu.com/usn/USN-2115-1http://www.ubuntu.com/usn/USN-2116-1https://bugzilla.redhat.com/show_bug.cgi?id=1031702https://github.com/torvalds/linux/commit/12d6e7538e2d418c08f082b1b44ffa5fb7270ed8https://github.com/torvalds/linux/commit/e40f193f5bb022e927a57a4f5d5194e4f12ddb74https://www.kernel.org/pub/linux/kernel/v3.x/patch-3.9.bz2
2013-11-20
Published