Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2013-2128

Опубликовано: 30 мар. 2010
Источник: redhat
CVSS2: 4.9
EPSS Низкий

Описание

The tcp_read_sock function in net/ipv4/tcp.c in the Linux kernel before 2.6.34 does not properly manage skb consumption, which allows local users to cause a denial of service (system crash) via a crafted splice system call for a TCP socket.

Отчет

This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2. This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6. Future kernel updates for Red Hat Enterprise Linux 6 may address this issue.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelNot affected
Red Hat Enterprise MRG 2realtime-kernelNot affected
OpenStack 3 for RHEL 6kernelFixedRHSA-2013:108016.07.2013
Red Hat Enterprise Linux 6kernelFixedRHSA-2013:105116.07.2013

Показывать по

Дополнительная информация

Статус:

Moderate
https://bugzilla.redhat.com/show_bug.cgi?id=968484Kernel: net: oops from tcp_collapse() when using splice(2)

EPSS

Процентиль: 27%
0.00095
Низкий

4.9 Medium

CVSS2

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 12 лет назад

The tcp_read_sock function in net/ipv4/tcp.c in the Linux kernel before 2.6.34 does not properly manage skb consumption, which allows local users to cause a denial of service (system crash) via a crafted splice system call for a TCP socket.

CVSS3: 5.5
nvd
больше 12 лет назад

The tcp_read_sock function in net/ipv4/tcp.c in the Linux kernel before 2.6.34 does not properly manage skb consumption, which allows local users to cause a denial of service (system crash) via a crafted splice system call for a TCP socket.

CVSS3: 5.5
debian
больше 12 лет назад

The tcp_read_sock function in net/ipv4/tcp.c in the Linux kernel befor ...

CVSS3: 5.5
github
больше 3 лет назад

The tcp_read_sock function in net/ipv4/tcp.c in the Linux kernel before 2.6.34 does not properly manage skb consumption, which allows local users to cause a denial of service (system crash) via a crafted splice system call for a TCP socket.

oracle-oval
около 12 лет назад

ELSA-2013-1051: kernel security and bug fix update (MODERATE)

EPSS

Процентиль: 27%
0.00095
Низкий

4.9 Medium

CVSS2