[USN-1796-1] Linux kernel vulnerabilities
Several security issues were fixed in the kernel.
Andrew Jones discovered a flaw with the xen_iret function in Linux kernel's
Xen virtualizeation. In the 32-bit Xen paravirt platform an unprivileged
guest OS user could exploit this flaw to cause a denial of service (crash
the system) or gain guest OS privilege. (CVE-2013-0228)
Emese Revfy discovered that in the Linux kernel signal handlers could leak
address information across an exec, making it possible to by pass ASLR
(Address Space Layout Randomization). A local user could use this flaw to
by pass ASLR to reliably deliver an exploit payload that would otherwise be
stopped (by ASLR). (CVE-2013-0914)
A memory use after free error was discover in the Linux kernel's tmpfs
filesystem. A local user could exploit this flaw to gain privileges or
cause a denial of service (system crash). (CVE-2013-1767)
Mateusz Guzik discovered a race in the Linux kernel's keyring. A local user
could exploit this flaw to cause a denial of service (system crash).
(CVE-2013-1792)
Mathias Krause discovered a memory leak in the Linux kernel's crypto report
API. A local user with CAP_NET_ADMIN could exploit this leak to examine
some of the kernel's stack memory. (CVE-2013-2546)
Mathias Krause discovered a memory leak in the Linux kernel's crypto report
API. A local user with CAP_NET_ADMIN could exploit this leak to examine
some of the kernel's heap memory. (CVE-2013-2547)
Mathias Krause discovered information leaks in the Linux kernel's crypto
algorithm report API. A local user could exploit these flaws to leak kernel
stack and heap memory contents. (CVE-2013-2548)
- ID
- USN-1796-1
- Severity
- medium
- Severity from
- CVE-2013-0228
- URL
- https://ubuntu.com/security/notices/USN-1796-1
- Published
-
2013-04-08T23:43:30
(11 years ago) - Modified
-
2013-04-08T23:43:30
(11 years ago) - Other Advisories
-
- ALAS-2013-200
- ALAS-2013-218
- ELSA-2013-0630
- ELSA-2013-0744
- ELSA-2013-1034
- ELSA-2013-1051
- ELSA-2013-2507
- ELSA-2013-2519
- ELSA-2013-2520
- ELSA-2013-2537
- ELSA-2013-2538
- FEDORA-2013-10695
- FEDORA-2013-12530
- FEDORA-2013-12990
- FEDORA-2013-13536
- FEDORA-2013-15151
- FEDORA-2013-16336
- FEDORA-2013-17010
- FEDORA-2013-17942
- FEDORA-2013-18364
- FEDORA-2013-18822
- FEDORA-2013-20748
- FEDORA-2013-21822
- FEDORA-2013-22695
- FEDORA-2013-2597
- FEDORA-2013-2635
- FEDORA-2013-2728
- FEDORA-2013-3086
- FEDORA-2013-3106
- FEDORA-2013-3223
- FEDORA-2013-3630
- FEDORA-2013-3893
- FEDORA-2013-3909
- FEDORA-2013-4012
- FEDORA-2013-4240
- FEDORA-2013-4357
- FEDORA-2013-5368
- FEDORA-2013-6041
- FEDORA-2013-6537
- FEDORA-2013-6999
- FEDORA-2013-9123
- RHSA-2013:0630
- RHSA-2013:0744
- RHSA-2013:1051
- SUSE-SU-2015:0481-1
- SUSE-SU-2015:0652-1
- USN-1756-1
- USN-1760-1
- USN-1767-1
- USN-1778-1
- USN-1781-1
- USN-1787-1
- USN-1788-1
- USN-1792-1
- USN-1793-1
- USN-1794-1
- USN-1795-1
- USN-1797-1
- USN-1798-1
- USN-1805-1
- USN-1808-1
- XSA-42
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | Exploits | PoC | Pubblication Date | Modification Date |
---|---|---|---|---|---|---|---|---|---|---|---|
# CVE | Description | CVSS | EPSS | EPSS Trend (30 days) | Affected Products | Weaknesses | Security Advisories | PoC | Pubblication Date | Modification Date |