Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2013-7446

Опубликовано: 28 дек. 2015
Источник: debian
EPSS Низкий

Описание

Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel before 4.3.3 allows local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.2.6-2package
linux-2.6removedpackage

Примечания

  • https://bugzilla.redhat.com/show_bug.cgi?id=1273845

  • https://groups.google.com/forum/#!topic/syzkaller/3twDUI4Cpm8

  • https://www.openwall.com/lists/oss-security/2015/11/18/9

  • Introduced by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ec0d215f9420564fc8286dcf93d2d068bb53a07e (v2.6.26-rc9)

  • Fixed by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7d267278a9ece963d77eefec61630223fce08c6c (v4.4-rc4)

EPSS

Процентиль: 4%
0.00022
Низкий

Связанные уязвимости

CVSS3: 5.3
ubuntu
больше 9 лет назад

Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel before 4.3.3 allows local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls.

redhat
почти 10 лет назад

Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel before 4.3.3 allows local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls.

CVSS3: 5.3
nvd
больше 9 лет назад

Use-after-free vulnerability in net/unix/af_unix.c in the Linux kernel before 4.3.3 allows local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls.

suse-cvrf
больше 9 лет назад

Security update for kernel live patch 11

suse-cvrf
больше 9 лет назад

Security update for kernel live patch 10

EPSS

Процентиль: 4%
0.00022
Низкий