CVE-2013-6378
published 2013-11-27CVE-2013-6378: The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service…
PriorityP418medium4.4CVSS 2.0
AVLACMAuSCNINAC
EPSS
0.38%
30.4th percentile
The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service (OOPS) by leveraging root privileges for a zero-length write operation.
Affected
243 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.11.10-1 (bookworm) | linux 3.11.10-1 (bookworm) |
| linux | linux_kernel | <= 3.12.1 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.4MEDIUMAV:L/AC:M/Au:S/C:N/I:N/A:C
osv4.4MEDIUM
vendor_ubuntu6.0MEDIUM
vendor_debian4.4LOW
vendor_redhat4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
A flaw in the handling of memory regions of the kernel virtual machine
(KVM) subsystem was discovered. A local user with the ability to assign a
device could exploit this flaw to cause a denial of service (memory
consumption). (CVE-2013-4592)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde and Fabian Yamaguchi reported a flaw in the
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
A flaw in the handling of memory regions of the kernel virtual machine
(KVM) subsystem was discovered. A local user with the ability to assign a
device could exploit this flaw to cause a denial of service (memory
consumption). (CVE-2013-4592)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde and Fabian Yamaguchi reported a flaw i
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
A flaw in the handling of memory region
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
A flaw in the handling of memory regions of the kernel virtual machine
(KVM) subsystem was discovered. A local user with the ability to assign a
device could exploit this flaw to cause a denial of service (memory
consumption). (CVE-2013-4592)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde and Fabian Yamaguchi reported a flaw in the driver f
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in t
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 6.0
CVE-2013-4299 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 5.8
CVE-2013-4345 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
A flaw was discovered in the Linux kernel's IP Virtual Server (IP_VS)
support. A local user with the CAP_NET_ADMIN capability could exploit this
flaw to gain additional administrative privileges. (CVE-2013-4588)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Dave Jones and Vince Weaver reported a flaw in the Linux kernel's per event
subsystem that allows normal users to enable function tracing. An
unprivileged local user could exploit this flaw to obtain potentially
sensitive information from the kernel. (CVE-2013-2930)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network f
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 5.8
CVE-2013-4345 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
A flaw was discovered in the Linux kernel's IP Virtual Server (IP_VS)
support. A local user with the CAP_NET_ADMIN capability could exploit this
flaw to gain additional administrative privileges. (CVE-2013-4588)
Nico Golde and Fabian Yamaguchi reported a flaw in the Linux kernel's
debugfs filesystem. An administrative local user could exploit this flaw to
cause a denial of service (OOPS). (CVE-2013-6378)
Nico Golde reported a flaw in the Linux kernel's userspace IO (uio) driver.
A local user could exploi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-01-03·CVSS 6.0
CVE-2013-4299 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's dm snapshot facility. A remote
authenticated user could exploit this flaw to obtain sensitive information
or modify/corrupt data. (CVE-2013-4299)
Hannes Frederic Sowa discovered a flaw in the Linux kernel's UDP
Fragmentation Offload (UFO). An unprivileged local user could exploit this
flaw to cause a denial of service (system crash) or possibly gain
administrative privileges. (CVE-2013-4470)
Multiple integer overflow flaws were discovered in the Alchemy LCD frame-
buffer drivers in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges. (CVE-2013-4511)
Nico Golde and Fabian Yamaguchi reported a flaw i
Red Hat
Kernel: drivers: libertas: potential oops in debugfs
vendor_redhat·2013-11-22·CVSS 4.4
CVE-2013-6378 [MEDIUM] Kernel: drivers: libertas: potential oops in debugfs
Kernel: drivers: libertas: potential oops in debugfs
The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service (OOPS) by leveraging root privileges for a zero-length write operation.
Statement: This issue does not affect the version of the kernel package as shipped with Red Hat Enterprise Linux 5.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2013-6378: linux - The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the...
vendor_debian·2013·CVSS 4.4
CVE-2013-6378 [MEDIUM] CVE-2013-6378: linux - The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the...
The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service (OOPS) by leveraging root privileges for a zero-length write operation.
Scope: local
bookworm: resolved (fixed in 3.11.10-1)
bullseye: resolved (fixed in 3.11.10-1)
forky: resolved (fixed in 3.11.10-1)
sid: resolved (fixed in 3.11.10-1)
trixie: resolved (fixed in 3.11.10-1)
GHSA
GHSA-v327-j93q-3fhj: The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs
ghsa_unreviewed·2022-05-17
CVE-2013-6378 [MEDIUM] GHSA-v327-j93q-3fhj: The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs
The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service (OOPS) by leveraging root privileges for a zero-length write operation.
OSV
CVE-2013-6378: The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs
osv·2013-11-27·CVSS 4.4
CVE-2013-6378 [MEDIUM] CVE-2013-6378: The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs
The lbs_debugfs_write function in drivers/net/wireless/libertas/debugfs.c in the Linux kernel through 3.12.1 allows local users to cause a denial of service (OOPS) by leveraging root privileges for a zero-length write operation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6378 Kernel: drivers: libertas: potential oops in debugfs [fedora-all]
bugzilla·2013-11-25·CVSS 4.4
CVE-2013-6378 [MEDIUM] CVE-2013-6378 Kernel: drivers: libertas: potential oops in debugfs [fedora-all]
CVE-2013-6378 Kernel: drivers: libertas: potential oops in debugfs [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue a
Bugzilla
CVE-2013-6378 Kernel: drivers: libertas: potential oops in debugfs
bugzilla·2013-11-22·CVSS 4.4
CVE-2013-6378 [MEDIUM] CVE-2013-6378 Kernel: drivers: libertas: potential oops in debugfs
CVE-2013-6378 Kernel: drivers: libertas: potential oops in debugfs
Linux kernel built with the Marvell 8xxx Libertas WLAN driver support
(CONFIG_LIBERTAS) is vulnerable to an invalid pointer dereference flaw. It could
occur while writing to a file under debugfs.
A privileged user could use this flaw to crash the system resulting in DoS.
Upstream fix:
-> https://git.kernel.org/linus/a497e47d4aec37aaf8f13509f3ef3d1f6a717d88
Reference:
-> http://seclists.org/oss-sec/2013/q4/330
Discussion:
Statement:
This issue does not affect the version of the kernel package as shipped with Red Hat Enterprise Linux 5.
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1034183]
---
kernel-3.11.10-300.fc20 has been pushed to the Fedora 20 stable repository. If problems still
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a497e47d4aec37aaf8f13509f3ef3d1f6a717d88http://linux.oracle.com/errata/ELSA-2014-0771.htmlhttp://linux.oracle.com/errata/ELSA-2014-3043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0100.htmlhttp://secunia.com/advisories/59262http://secunia.com/advisories/59309http://secunia.com/advisories/59406http://www.openwall.com/lists/oss-security/2013/11/22/5http://www.securityfocus.com/bid/63886http://www.ubuntu.com/usn/USN-2064-1http://www.ubuntu.com/usn/USN-2065-1http://www.ubuntu.com/usn/USN-2066-1http://www.ubuntu.com/usn/USN-2067-1http://www.ubuntu.com/usn/USN-2070-1http://www.ubuntu.com/usn/USN-2075-1http://www.ubuntu.com/usn/USN-2111-1http://www.ubuntu.com/usn/USN-2112-1http://www.ubuntu.com/usn/USN-2114-1http://www.ubuntu.com/usn/USN-2115-1http://www.ubuntu.com/usn/USN-2116-1https://bugzilla.redhat.com/show_bug.cgi?id=1033578https://github.com/torvalds/linux/commit/a497e47d4aec37aaf8f13509f3ef3d1f6a717d88http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=a497e47d4aec37aaf8f13509f3ef3d1f6a717d88http://linux.oracle.com/errata/ELSA-2014-0771.htmlhttp://linux.oracle.com/errata/ELSA-2014-3043.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.htmlhttp://lists.opensuse.org/opensuse-updates/2014-02/msg00045.htmlhttp://rhn.redhat.com/errata/RHSA-2014-0100.htmlhttp://secunia.com/advisories/59262http://secunia.com/advisories/59309http://secunia.com/advisories/59406http://www.openwall.com/lists/oss-security/2013/11/22/5http://www.securityfocus.com/bid/63886http://www.ubuntu.com/usn/USN-2064-1http://www.ubuntu.com/usn/USN-2065-1http://www.ubuntu.com/usn/USN-2066-1http://www.ubuntu.com/usn/USN-2067-1http://www.ubuntu.com/usn/USN-2070-1http://www.ubuntu.com/usn/USN-2075-1http://www.ubuntu.com/usn/USN-2111-1http://www.ubuntu.com/usn/USN-2112-1http://www.ubuntu.com/usn/USN-2114-1http://www.ubuntu.com/usn/USN-2115-1http://www.ubuntu.com/usn/USN-2116-1https://bugzilla.redhat.com/show_bug.cgi?id=1033578https://github.com/torvalds/linux/commit/a497e47d4aec37aaf8f13509f3ef3d1f6a717d88
2013-11-27
Published