CVE-2013-2147

CVSS v2.0 2.1 (Low)
21% Progress
EPSS 0.04 % (11th)
0.04% Progress
Affected Products 2
Advisories 29

The HP Smart Array controller disk-array driver and Compaq SMART2 controller disk-array driver in the Linux kernel through 3.9.4 do not initialize certain data structures, which allows local users to obtain sensitive information from kernel memory via (1) a crafted IDAGETPCIINFO command for a /dev/ida device, related to the ida_locked_ioctl function in drivers/block/cpqarray.c or (2) a crafted CCISS_PASSTHRU32 command for a /dev/cciss device, related to the cciss_ioctl32_passthru function in drivers/block/cciss.c.

Weaknesses
CWE-399
Resource Management Errors
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2013-06-07 14:03:19
(11 years ago)
Updated Date
2018-01-09 02:29:02
(6 years ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel 3.9.4 and prior versions cpe:2.3:o:linux:linux_kernel <= 3.9.4
  Linux Kernel 3.9 Rc1 cpe:2.3:o:linux:linux_kernel:3.9:rc1
  Linux Kernel 3.9 Rc2 cpe:2.3:o:linux:linux_kernel:3.9:rc2
  Linux Kernel 3.9 Rc3 cpe:2.3:o:linux:linux_kernel:3.9:rc3
  Linux Kernel 3.9 Rc4 cpe:2.3:o:linux:linux_kernel:3.9:rc4
  Linux Kernel 3.9 Rc5 cpe:2.3:o:linux:linux_kernel:3.9:rc5
  Linux Kernel 3.9 Rc6 cpe:2.3:o:linux:linux_kernel:3.9:rc6
  Linux Kernel 3.9 Rc7 cpe:2.3:o:linux:linux_kernel:3.9:rc7
  Linux Kernel 3.9.0 cpe:2.3:o:linux:linux_kernel:3.9.0
  Linux Kernel 3.9.1 cpe:2.3:o:linux:linux_kernel:3.9.1
  Linux Kernel 3.9.2 cpe:2.3:o:linux:linux_kernel:3.9.2
  Linux Kernel 3.9.3 cpe:2.3:o:linux:linux_kernel:3.9.3

Configuration #2

    CPE23 From Up To
  Suse Linux Enterprise Server 10 SP4 cpe:2.3:o:suse:linux_enterprise_server:10:sp4
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...