CVE-2015-8374
published 2015-12-28CVE-2015-8374: fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information…
PriorityP413medium4CVSS 3.0
AVLACLPRNUINSUCLINAN
EPSS
0.50%
39.9th percentile
fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.2.6-2 (bookworm) | linux 4.2.6-2 (bookworm) |
| linux | linux_kernel | <= 4.3.2 | — |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 4.2.6-2 | 4.2.6-2 |
| linux | linux_kernel | >= 0 < 3.13.0-77.121 | 3.13.0-77.121 |
CVSS provenance
nvdv3.04.0MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv5.3MEDIUM
vendor_ubuntu5.3MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attack
Ubuntu
Linux kernel (Vivid HWE) vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (Vivid HWE) vulnerabilities
Title: Linux kernel (Vivid HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A
Ubuntu
Linux kernel (Wily HWE) vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (Wily HWE) vulnerabilities
Title: Linux kernel (Wily HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attack
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of servic
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A
Ubuntu
Linux kernel (Raspberry Pi 2) vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (Raspberry Pi 2) vulnerabilities
Title: Linux kernel (Raspberry Pi 2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of se
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system cra
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2016-02-01·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/ppp coul
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2016-02-01·CVSS 5.3
CVE-2013-7446 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
郭永刚 discovered that the ppp implementation in the Linux kernel did
not ensure that certain slot numbers are valid. A local attacker with the
privilege to call ioctl() on /dev/
Red Hat
kernel: Information leak when truncating of compressed/inlined extents on BTRFS
vendor_redhat·2015-10-16·CVSS 4.0
CVE-2015-8374 [MEDIUM] CWE-200 kernel: Information leak when truncating of compressed/inlined extents on BTRFS
kernel: Information leak when truncating of compressed/inlined extents on BTRFS
fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.
An information-leak vulnerability was found in the kernel when it truncated a file to a smaller size which consisted of an inline extent that was compressed. The data between the new file size and the old file size was not discarded and the number of bytes used by the inode were not correctly decremented, which gave the wrong report for callers of the stat(2) syscall. This wasted metadata space and allowed for the truncated data to be leaked, and data corruption or loss to occur. A caller of the clone ioctl could exploit
Debian
CVE-2015-8374: linux - fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline e...
vendor_debian·2015·CVSS 4.0
CVE-2015-8374 [MEDIUM] CVE-2015-8374: linux - fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline e...
fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.
Scope: local
bookworm: resolved (fixed in 4.2.6-2)
bullseye: resolved (fixed in 4.2.6-2)
forky: resolved (fixed in 4.2.6-2)
sid: resolved (fixed in 4.2.6-2)
trixie: resolved (fixed in 4.2.6-2)
GHSA
GHSA-pv6w-frj8-84fg: fs/btrfs/inode
ghsa_unreviewed·2022-05-14
CVE-2015-8374 [MEDIUM] CWE-200 GHSA-pv6w-frj8-84fg: fs/btrfs/inode
fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.
OSV
linux vulnerabilities
osv·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attacker could use this to cause
a denial of service (system crash). (CVE-2015-7
OSV
linux-lts-wily vulnerabilities
osv·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] linux-lts-wily vulnerabilities
linux-lts-wily vulnerabilities
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)
Sasha Levin discovered that the Reliable Da
OSV
linux-lts-utopic vulnerabilities
osv·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
It was discovered that the Linux kernel keyring subsystem contained a race
between read and revoke operations. A local attacker could use this to
cause a denial of service (system crash). (CVE-2015-7550)
Sasha Levin discovered that the Reliable
OSV
linux-lts-vivid vulnerabilities
osv·2016-02-02·CVSS 5.3
CVE-2013-7446 [MEDIUM] linux-lts-vivid vulnerabilities
linux-lts-vivid vulnerabilities
It was discovered that a use-after-free vulnerability existed in the
AF_UNIX implementation in the Linux kernel. A local attacker could use
crafted epoll_ctl calls to cause a denial of service (system crash) or
expose sensitive information. (CVE-2013-7446)
It was discovered that the KVM implementation in the Linux kernel did not
properly restore the values of the Programmable Interrupt Timer (PIT). A
user-assisted attacker in a KVM guest could cause a denial of service in
the host (system crash). (CVE-2015-7513)
Sasha Levin discovered that the Reliable Datagram Sockets (RDS)
implementation in the Linux kernel had a race condition when checking
whether a socket was bound or not. A local attacker could use this to cause
a denial of service (system crash). (
OSV
CVE-2015-8374: fs/btrfs/inode
osv·2015-12-28·CVSS 4.0
CVE-2015-8374 [MEDIUM] CVE-2015-8374: fs/btrfs/inode
fs/btrfs/inode.c in the Linux kernel before 4.3.3 mishandles compressed inline extents, which allows local users to obtain sensitive pre-truncation information from a file via a clone action.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8374 kernel: Information leak when truncating of compressed/inlined extents [fedora-all]
bugzilla·2015-11-27·CVSS 4.0
CVE-2015-8374 [MEDIUM] CVE-2015-8374 kernel: Information leak when truncating of compressed/inlined extents [fedora-all]
CVE-2015-8374 kernel: Information leak when truncating of compressed/inlined extents [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple su
Bugzilla
CVE-2015-8374 kernel: Information leak when truncating of compressed/inlined extents on BTRFS
bugzilla·2015-11-27·CVSS 4.0
CVE-2015-8374 [MEDIUM] CVE-2015-8374 kernel: Information leak when truncating of compressed/inlined extents on BTRFS
CVE-2015-8374 kernel: Information leak when truncating of compressed/inlined extents on BTRFS
An information leak vulnerability was found when truncating a file to a smaller size which consists of an inline extent that is compressed. The data between the new file size and the old file size were not discarded, wasting metadata space and allowing for the truncated data to be leaked and the data corruption/loss to occur. The number of bytes used by the inode were not correctly decremented, which gives wrong report for callers of the stat(2) syscall. It is possible for a caller of the clone ioctl to actually read the data that was truncated, allowing for a security breach without requiring root access to the system, using only standard filesystem operations.
Upstream patch (includes reproduc
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0305cd5f7fca85dae392b9ba85b116896eb7c1c7http://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2584.htmlhttp://www.debian.org/security/2015/dsa-3426http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.3http://www.openwall.com/lists/oss-security/2015/11/27/2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlhttp://www.securityfocus.com/bid/78219http://www.securitytracker.com/id/1034895http://www.ubuntu.com/usn/USN-2886-1http://www.ubuntu.com/usn/USN-2887-1http://www.ubuntu.com/usn/USN-2887-2http://www.ubuntu.com/usn/USN-2888-1http://www.ubuntu.com/usn/USN-2889-1http://www.ubuntu.com/usn/USN-2889-2http://www.ubuntu.com/usn/USN-2890-1http://www.ubuntu.com/usn/USN-2890-2http://www.ubuntu.com/usn/USN-2890-3https://bugzilla.redhat.com/show_bug.cgi?id=1286261https://github.com/torvalds/linux/commit/0305cd5f7fca85dae392b9ba85b116896eb7c1c7http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0305cd5f7fca85dae392b9ba85b116896eb7c1c7http://rhn.redhat.com/errata/RHSA-2016-2574.htmlhttp://rhn.redhat.com/errata/RHSA-2016-2584.htmlhttp://www.debian.org/security/2015/dsa-3426http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.3.3http://www.openwall.com/lists/oss-security/2015/11/27/2http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.htmlhttp://www.oracle.com/technetwork/topics/security/ovmbulletinoct2016-3090547.htmlhttp://www.securityfocus.com/bid/78219http://www.securitytracker.com/id/1034895http://www.ubuntu.com/usn/USN-2886-1http://www.ubuntu.com/usn/USN-2887-1http://www.ubuntu.com/usn/USN-2887-2http://www.ubuntu.com/usn/USN-2888-1http://www.ubuntu.com/usn/USN-2889-1http://www.ubuntu.com/usn/USN-2889-2http://www.ubuntu.com/usn/USN-2890-1http://www.ubuntu.com/usn/USN-2890-2http://www.ubuntu.com/usn/USN-2890-3https://bugzilla.redhat.com/show_bug.cgi?id=1286261https://github.com/torvalds/linux/commit/0305cd5f7fca85dae392b9ba85b116896eb7c1c7
2015-12-28
Published