Vulnerability CVE-2013-4254


Published: 2013-08-24   Modified: 2013-08-25

Description:
The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by adding a hardware event to an event group led by a software event.

See advisories in our WLB2 database:
Topic
Author
Date
High
Linux Kernel 3.11-rc ARM/perf priviledge escalation
Vince Weaver
15.08.2013

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:L/AC:M/Au:N/C:C/I:C/A:C)

CVSS Base Score
Impact Subscore
Exploitability Subscore
6.9/10
10/10
3.4/10
Exploit range
Attack complexity
Authentication
Local
Medium
No required
Confidentiality impact
Integrity impact
Availability impact
Complete
Complete
Complete
Affected software
Linux -> Linux kernel 

 References:
https://github.com/torvalds/linux/commit/c95eb3184ea1a3a2551df57190c81da695e2144b
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=c95eb3184ea1a3a2551df57190c81da695e2144b
https://bugzilla.redhat.com/show_bug.cgi?id=998878
http://www.openwall.com/lists/oss-security/2013/08/16/6
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.8

Copyright 2024, cxsecurity.com

 

Back to Top