The Linux kernel before 3.12.4 updates certain length values before ensuring that associated data structures have been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call, related to net/ipv4/ping.c, net/ipv4/raw.c, net/ipv4/udp.c, net/ipv6/raw.c, and net/ipv6/udp.c.
Metrics
Affected Vendors & Products
Advisories
| Source | ID | Title |
|---|---|---|
Debian DSA |
DSA-2906-1 | linux-2.6 security update |
EUVD |
EUVD-2013-7041 | The Linux kernel before 3.12.4 updates certain length values before ensuring that associated data structures have been initialized, which allows local users to obtain sensitive information from kernel stack memory via a (1) recvfrom, (2) recvmmsg, or (3) recvmsg system call, related to net/ipv4/ping.c, net/ipv4/raw.c, net/ipv4/udp.c, net/ipv6/raw.c, and net/ipv6/udp.c. |
Ubuntu USN |
USN-2107-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-2108-1 | Linux kernel (EC2) vulnerabilities |
Ubuntu USN |
USN-2109-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-2110-1 | Linux kernel (OMAP4) vulnerabilities |
Ubuntu USN |
USN-2113-1 | Linux kernel (Saucy HWE) vulnerabilities |
Ubuntu USN |
USN-2117-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-2135-1 | Linux kernel (Quantal HWE) vulnerabilities |
Ubuntu USN |
USN-2136-1 | Linux kernel (Raring HWE) vulnerabilities |
Ubuntu USN |
USN-2138-1 | Linux kernel vulnerabilities |
Ubuntu USN |
USN-2139-1 | Linux kernel (OMAP4) vulnerabilities |
Ubuntu USN |
USN-2141-1 | Linux kernel (OMAP4) vulnerabilities |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
No history.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-08-06T18:01:20.195Z
Reserved: 2014-01-05T00:00:00
Link: CVE-2013-7263
No data.
Status : Deferred
Published: 2014-01-06T16:55:09.147
Modified: 2025-04-11T00:51:21.963
Link: CVE-2013-7263
OpenCVE Enrichment
No data.
Debian DSA
EUVD
Ubuntu USN