CVE-2013-7421

CVSS v2.0 2.1 (Low)
21% Progress
EPSS 0.04 % (11th)
0.04% Progress
Affected Products 4
Advisories 13

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.

Weaknesses
CWE-269
Improper Privilege Management
Related CVEs
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2015-03-02 11:59:00
(9 years ago)
Updated Date
2023-11-07 02:18:03
(10 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:lts
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:lts
  Canonical Ubuntu Linux 14.10 cpe:2.3:o:canonical:ubuntu_linux:14.10

Configuration #2

    CPE23 From Up To
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0
  Debian Linux 8.0 cpe:2.3:o:debian:debian_linux:8.0

Configuration #3

    CPE23 From Up To
  Linux Kernel prior 3.18.5 version cpe:2.3:o:linux:linux_kernel < 3.18.5

Configuration #4

    CPE23 From Up To
  Oracle Linux 5 cpe:2.3:o:oracle:linux:5:-
  Oracle Linux 6 cpe:2.3:o:oracle:linux:6:-
  Oracle Linux 7 cpe:2.3:o:oracle:linux:7:-
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...