Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2094

Опубликовано: 14 мая 2013
Источник: redhat
CVSS2: 7.2
EPSS Средний

Описание

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

Отчет

This issue does not affect the kernel packages as shipped with Red Hat Enterprise Linux 5 because we did not backport upstream commit b0a873eb that introduced this issue. This issue was addressed in Red Hat Enterprise Linux 6 via RHSA-2013:0830 (https://rhn.redhat.com/errata/RHSA-2013-0830.html), Red Hat Enterprise Linux 6.1 Extended update support via RHSA-2013:0841 (https://rhn.redhat.com/errata/RHSA-2013-0841.html), Red Hat Enterprise Linux 6.2 Extended update support via RHSA-2013:0840 (https://rhn.redhat.com/errata/RHSA-2013-0840.html), Red Hat Enterprise Linux 6.3 Extended Update Support via RHSA-2013:0832 (https://rhn.redhat.com/errata/RHSA-2013-0832.html), and Red Hat Enterprise MRG 2 via RHSA-2013:0829 (https://rhn.redhat.com/errata/RHSA-2013-0829.html). Red Hat Enterprise Linux 6.0 was not affected by this flaw. Refer to https://access.redhat.com/site/solutions/373743 for further information.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise Linux 6kernelFixedRHSA-2013:083016.05.2013
Red Hat Enterprise Linux 6.1 EUS - Server OnlykernelFixedRHSA-2013:084120.05.2013
Red Hat Enterprise Linux 6.2 EUS - Server and Compute Node OnlykernelFixedRHSA-2013:084020.05.2013
Red Hat Enterprise Linux 6.3 EUS - Server and Compute Node OnlykernelFixedRHSA-2013:083217.05.2013
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2013:082920.05.2013

Показывать по

Дополнительная информация

Статус:

Important
Дефект:
CWE-839->CWE-129->CWE-119
https://bugzilla.redhat.com/show_bug.cgi?id=962792kernel: perf_swevent_enabled array out-of-bound access

EPSS

Процентиль: 98%
0.63396
Средний

7.2 High

CVSS2

Связанные уязвимости

CVSS3: 8.4
ubuntu
около 12 лет назад

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

CVSS3: 8.4
nvd
около 12 лет назад

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

CVSS3: 8.4
msrc
больше 1 года назад

Описание отсутствует

CVSS3: 8.4
debian
около 12 лет назад

The perf_swevent_init function in kernel/events/core.c in the Linux ke ...

CVSS3: 8.4
github
около 3 лет назад

The perf_swevent_init function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perf_event_open system call.

EPSS

Процентиль: 98%
0.63396
Средний

7.2 High

CVSS2