CVE-2013-3301

CVSS v2.0 7.2 (High)
72% Progress
EPSS 0.06 % (27th)
0.06% Progress
Affected Products 6
Advisories 15

The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.

Weaknesses
CWE-NVD-Other
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2013-04-29 14:55:04
(11 years ago)
Updated Date
2024-02-02 16:33:41
(7 months ago)

Affected Products

Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 3.1 version and prior 3.2.44 version cpe:2.3:o:linux:linux_kernel >= 3.1 < 3.2.44
  Linux Kernel from 3.3 version and prior 3.4.49 version cpe:2.3:o:linux:linux_kernel >= 3.3 < 3.4.49
  Linux Kernel from 3.5 version and prior 3.8.8 version cpe:2.3:o:linux:linux_kernel >= 3.5 < 3.8.8

Configuration #2

    CPE23 From Up To
  Redhat Enterprise Linux 6.0 cpe:2.3:o:redhat:enterprise_linux:6.0
  Redhat Enterprise Mrg 2.0 cpe:2.3:o:redhat:enterprise_mrg:2.0

Configuration #3

    CPE23 From Up To
  Suse Linux Enterprise Desktop 11 SP3 cpe:2.3:o:suse:linux_enterprise_desktop:11:sp3
  Suse Linux Enterprise High Availability Extension 11 SP3 cpe:2.3:o:suse:linux_enterprise_high_availability_extension:11:sp3
  Suse Linux Enterprise Server 11 SP3 For cpe:2.3:o:suse:linux_enterprise_server:11:sp3:*:*:*:-
  Suse Linux Enterprise Server 11 SP3 Vmware Edition cpe:2.3:o:suse:linux_enterprise_server:11:sp3:vmware
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...