HIGH · 7.2

CVE-2013-3301

The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leve...

Vulnerability Description

The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.

CVSS Score

7.2

HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C
Confidentiality
COMPLETE
Integrity
COMPLETE
Availability
COMPLETE

Affected Products

VendorProductVersions
LinuxLinux Kernel>= 3.1, < 3.2.44
RedhatEnterprise Linux6.0
RedhatEnterprise Mrg2.0
SuseLinux Enterprise Desktop11
SuseLinux Enterprise High Availability Extension11
SuseLinux Enterprise Server11

References

FAQ

What is CVE-2013-3301?

CVE-2013-3301 is a vulnerability with a CVSS score of 7.2 (HIGH). The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leve...

How severe is CVE-2013-3301?

CVE-2013-3301 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2013-3301?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Enterprise Linux, Redhat Enterprise Mrg, Suse Linux Enterprise Desktop, Suse Linux Enterprise High Availability Extension.