CVE-2013-6382
published 2013-11-27CVE-2013-6382: Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or…
PriorityP415medium4CVSS 2.0
AVLACHAuNCNINAC
EPSS
0.57%
44.6th percentile
Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) XFS_IOC_ATTRLIST_BY_HANDLE or (2) XFS_IOC_ATTRLIST_BY_HANDLE_32 ioctl call with a crafted length value, related to the xfs_attrlist_by_handle function in fs/xfs/xfs_ioctl.c and the xfs_compat_attrlist_by_handle function in fs/xfs/xfs_ioctl32.c.
Affected
243 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.11.10-1 (bookworm) | linux 3.11.10-1 (bookworm) |
| linux | linux_kernel | <= 3.12.1 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:L/AC:H/Au:N/C:N/I:N/A:C
osv4.0MEDIUM
vendor_ubuntu7.1HIGH
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2014-04-01·CVSS 5.8
CVE-2013-4345 [MEDIUM] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Nico Golde and Fabian Yamaguchi reported buffer underflow errors in the
implementation of the XFS filesystem in the Linux kernel. A local user with
CAP_SYS_ADMIN could exploit these flaw to cause a denial of service (memory
corruption) or possibly other unspecified issues. (CVE-2013-6382)
An information leak was discovered in the Linux kernel when built with the
NetFilter Connection Tracking (NF_CONNTRACK) support for IRC protocol
(NF_NAT_IRC). A remote attacker could exploit this flaw to obt
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-03-07·CVSS 4.3
CVE-2013-4579 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Kernel
Virtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service or host OS system crash.
(CVE-2013-6367)
Andrew Honig
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-03-07·CVSS 4.3
CVE-2013-4579 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Kernel
Virtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service or host OS system crash.
(CVE-2013-6367)
Andrew Honig
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-03-07·CVSS 4.3
CVE-2013-4579 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Kernel
Virtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service or host OS system crash.
(CVE-2013-6367)
Andrew Honig reporte
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2014-03-07·CVSS 4.3
CVE-2013-4579 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Kernel
Virtual Machine (KVM) subsystem if the Linux kernel. A guest OS user could
exploit this flaw to cause a denial of service or host OS system crash.
(CVE-2013-6367)
Andrew
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-03-06·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-03-05·CVSS 2.1
CVE-2013-0160 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the Linux kernel when inotify is used
to monitor the /dev/ptmx device. A local user could exploit this flaw to
discover keystroke timing and potentially discover sensitive information
like password length. (CVE-2013-0160)
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig repo
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 7.1
CVE-2013-4563 [HIGH] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Saran Neti reported a flaw in the ipv6 UDP Fragmentation Offload (UFI) in
the Linux kernel. A remote attacker could exploit this flaw to cause a
denial of service (panic). (CVE-2013-4563)
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct functi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 7.1
CVE-2013-4563 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Saran Neti reported a flaw in the ipv6 UDP Fragmentation Offload (UFI) in
the Linux kernel. A remote attacker could exploit this flaw to cause a
denial of service (panic). (CVE-2013-4563)
Mathy Vanhoef discovered an error in the the way the ath9k driver was
handling the BSSID masking. A remote attacker could exploit this error to
discover the original MAC address after a spoofing atack. (CVE-2013-4579)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsystem. A local user could
exploit this flaw to gain privileges on the host machine. (CVE-2013-4587)
Andrew Honig reported a flaw in the apic_get_tmcct function of the Ke
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-02-18·CVSS 3.3
CVE-2013-2929 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Vasily Kulikov reported a flaw in the Linux kernel's implementation of
ptrace. An unprivileged local user could exploit this flaw to obtain
sensitive information from kernel memory. (CVE-2013-2929)
Stephan Mueller reported an error in the Linux kernel's ansi cprng random
number generator. This flaw makes it easier for a local attacker to break
cryptographic protections. (CVE-2013-4345)
Jason Wang discovered a bug in the network flow dissector in the Linux
kernel. A remote attacker could exploit this flaw to cause a denial of
service (infinite loop). (CVE-2013-4348)
Andrew Honig reported a flaw in the Linux Kernel's kvm_vm_ioctl_create_vcpu
function of the Kernel Virtual Machine (KVM) subsyst
Red Hat
Kernel: fs: xfs: missing check for ZERO_SIZE_PTR
vendor_redhat·2013-11-22·CVSS 4.0
CVE-2013-6382 [MEDIUM] Kernel: fs: xfs: missing check for ZERO_SIZE_PTR
Kernel: fs: xfs: missing check for ZERO_SIZE_PTR
Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) XFS_IOC_ATTRLIST_BY_HANDLE or (2) XFS_IOC_ATTRLIST_BY_HANDLE_32 ioctl call with a crafted length value, related to the xfs_attrlist_by_handle function in fs/xfs/xfs_ioctl.c and the xfs_compat_attrlist_by_handle function in fs/xfs/xfs_ioctl32.c.
Statement: The Red Hat Security Response Team does not consider this issue to be a security flaw due to the full root-like privileges (CAP_SYS_ADMIN) needed for successful exploitation.
Package: kernel (Red Hat Enterprise Linux 5) - Will not fix
Packag
Debian
CVE-2013-6382: linux - Multiple buffer underflows in the XFS implementation in the Linux kernel through...
vendor_debian·2013·CVSS 4.0
CVE-2013-6382 [MEDIUM] CVE-2013-6382: linux - Multiple buffer underflows in the XFS implementation in the Linux kernel through...
Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) XFS_IOC_ATTRLIST_BY_HANDLE or (2) XFS_IOC_ATTRLIST_BY_HANDLE_32 ioctl call with a crafted length value, related to the xfs_attrlist_by_handle function in fs/xfs/xfs_ioctl.c and the xfs_compat_attrlist_by_handle function in fs/xfs/xfs_ioctl32.c.
Scope: local
bookworm: resolved (fixed in 3.11.10-1)
bullseye: resolved (fixed in 3.11.10-1)
forky: resolved (fixed in 3.11.10-1)
sid: resolved (fixed in 3.11.10-1)
trixie: resolved (fixed in 3.11.10-1)
GHSA
GHSA-q75g-mf48-c9pw: Multiple buffer underflows in the XFS implementation in the Linux kernel through 3
ghsa_unreviewed·2022-05-17
CVE-2013-6382 [MEDIUM] CWE-119 GHSA-q75g-mf48-c9pw: Multiple buffer underflows in the XFS implementation in the Linux kernel through 3
Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) XFS_IOC_ATTRLIST_BY_HANDLE or (2) XFS_IOC_ATTRLIST_BY_HANDLE_32 ioctl call with a crafted length value, related to the xfs_attrlist_by_handle function in fs/xfs/xfs_ioctl.c and the xfs_compat_attrlist_by_handle function in fs/xfs/xfs_ioctl32.c.
OSV
CVE-2013-6382: Multiple buffer underflows in the XFS implementation in the Linux kernel through 3
osv·2013-11-27·CVSS 4.0
CVE-2013-6382 [MEDIUM] CVE-2013-6382: Multiple buffer underflows in the XFS implementation in the Linux kernel through 3
Multiple buffer underflows in the XFS implementation in the Linux kernel through 3.12.1 allow local users to cause a denial of service (memory corruption) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for a (1) XFS_IOC_ATTRLIST_BY_HANDLE or (2) XFS_IOC_ATTRLIST_BY_HANDLE_32 ioctl call with a crafted length value, related to the xfs_attrlist_by_handle function in fs/xfs/xfs_ioctl.c and the xfs_compat_attrlist_by_handle function in fs/xfs/xfs_ioctl32.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2013-6382 Kernel: fs: xfs: missing check for ZERO_SIZE_PTR [fedora-all]
bugzilla·2013-11-26·CVSS 4.0
CVE-2013-6382 [MEDIUM] CVE-2013-6382 Kernel: fs: xfs: missing check for ZERO_SIZE_PTR [fedora-all]
CVE-2013-6382 Kernel: fs: xfs: missing check for ZERO_SIZE_PTR [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue affec
Bugzilla
CVE-2013-6382 Kernel: fs: xfs: missing check for ZERO_SIZE_PTR
bugzilla·2013-11-22·CVSS 4.0
CVE-2013-6382 [MEDIUM] CVE-2013-6382 Kernel: fs: xfs: missing check for ZERO_SIZE_PTR
CVE-2013-6382 Kernel: fs: xfs: missing check for ZERO_SIZE_PTR
Linux kernel built a XFS file system support(CONFIG_XFS_FS) along with the
Compat mode(CONFIG_COMPAT) enabled, is vulnerable to an invalid pointer
dereference flaw. It could occur while doing a Compat ioctl call with a
XFS_IOC_ATTRLIST_BY_HANDLE command.
A privileged(CAP_SYS_ADMIN) user/program could use this flaw to either make the system dereference invalid pointer or potentially cause memory corruption.
Upstream fix:
-> http://www.spinics.net/lists/xfs/msg23343.html
Reference:
-> http://seclists.org/oss-sec/2013/q4/330
Discussion:
nt
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1034670]
---
Statement:
The Red Hat Security Response Team does not consider this issue to be a security fla
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
http://www.openwall.com/lists/oss-security/2013/11/22/5http://www.securityfocus.com/bid/63889http://www.spinics.net/lists/xfs/msg23343.htmlhttp://www.ubuntu.com/usn/USN-2109-1http://www.ubuntu.com/usn/USN-2110-1http://www.ubuntu.com/usn/USN-2113-1http://www.ubuntu.com/usn/USN-2117-1http://www.ubuntu.com/usn/USN-2128-1http://www.ubuntu.com/usn/USN-2129-1http://www.ubuntu.com/usn/USN-2135-1http://www.ubuntu.com/usn/USN-2138-1http://www.ubuntu.com/usn/USN-2139-1http://www.ubuntu.com/usn/USN-2141-1http://www.ubuntu.com/usn/USN-2158-1https://bugzilla.redhat.com/show_bug.cgi?id=1033603http://www.openwall.com/lists/oss-security/2013/11/22/5http://www.securityfocus.com/bid/63889http://www.spinics.net/lists/xfs/msg23343.htmlhttp://www.ubuntu.com/usn/USN-2109-1http://www.ubuntu.com/usn/USN-2110-1http://www.ubuntu.com/usn/USN-2113-1http://www.ubuntu.com/usn/USN-2117-1http://www.ubuntu.com/usn/USN-2128-1http://www.ubuntu.com/usn/USN-2129-1http://www.ubuntu.com/usn/USN-2135-1http://www.ubuntu.com/usn/USN-2138-1http://www.ubuntu.com/usn/USN-2139-1http://www.ubuntu.com/usn/USN-2141-1http://www.ubuntu.com/usn/USN-2158-1https://bugzilla.redhat.com/show_bug.cgi?id=1033603
2013-11-27
Published