LWN.net Logo

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CVE-2013-1767 CVE-2013-1774
Created:March 4, 2013 Updated:March 22, 2013
Description: From the Mageia advisory:

Linux kernel is prone to a local privilege-escalation vulnerability due to a tmpfs use-after-free error. Local attackers can exploit the issue to execute arbitrary code with kernel privileges or to crash the kernel, effectively denying service to legitimate users (CVE-2013-1767).

Linux kernel built with Edgeport USB serial converter driver io_ti, is vulnerable to a NULL pointer dereference flaw. It happens if the device is disconnected while corresponding /dev/ttyUSB? file is in use. An unprivileged user could use this flaw to crash the system, resulting DoS (CVE-2013-1774).

Alerts:
Mageia MGASA-2013-0079 2013-03-02
Mageia MGASA-2013-0080 2013-03-02
Mageia MGASA-2013-0081 2013-03-02
Mageia MGASA-2013-0082 2013-03-02
Mageia MGASA-2013-0083 2013-03-02
Fedora FEDORA-2013-3223 2013-03-02
Ubuntu USN-1767-1 2013-03-18
Fedora FEDORA-2013-3909 2013-03-22
Ubuntu USN-1781-1 2013-03-26
Ubuntu USN-1787-1 2013-04-02
Ubuntu USN-1788-1 2013-04-03

(Log in to post comments)

Copyright © 2013, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds