The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.
Metrics
Affected Vendors & Products
References
History
No history.
MITRE
Status: PUBLISHED
Assigner: redhat
Published: 2013-04-29T10:00:00
Updated: 2024-08-06T16:07:37.739Z
Reserved: 2013-04-28T00:00:00
Link: CVE-2013-3301
Vulnrichment
No data.
NVD
Status : Analyzed
Published: 2013-04-29T14:55:04.630
Modified: 2024-02-02T16:33:41.383
Link: CVE-2013-3301
Redhat