CVE-2013-0268

Priority
Medium
Description
The msr_open function in arch/x86/kernel/msr.c in the Linux kernel before
3.7.6 allows local users to bypass intended capability restrictions by
executing a crafted application as root, as demonstrated by msr32.c.
Ubuntu-Description
A flaw was reported in the permission checks done by the Linux kernel for
/dev/cpu/*/msr. A local root user with all capabilities dropped could
exploit this flaw to execute code with full root capabilities.
References
Bugs
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):released (3.2.0-1615.23)
Ubuntu 12.10 (Quantal Quetzal):released (3.5.0-1610.14)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.32-351.62)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):released (3.0.0-32.50~lucid1)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (abandoned)
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):released (3.5.0-26.40~precise1)
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Patches:
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Source: linux (LP Ubuntu Debian)
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):released (2.6.32-46.105)
Ubuntu 12.04 LTS (Precise Pangolin):released (3.2.0-39.62)
Ubuntu 12.10 (Quantal Quetzal):released (3.5.0-26.40)
Ubuntu 13.04 (Raring Ringtail):not-affected (3.8.0-4.8)
Ubuntu 13.10 (Saucy Salamander):not-affected (3.8.0-4.8)
Patches:
Introduced by 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2Fixed by c903f0456bc69176912dee6dd25c6a66ee1aed00
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):released (3.2.0-1427.36)
Ubuntu 12.10 (Quantal Quetzal):released (3.5.0-221.30)
Ubuntu 13.04 (Raring Ringtail):not-affected (3.5.0-221.30)
Ubuntu 13.10 (Saucy Salamander):not-affected (3.5.0-221.30)
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life, does not affect buildd)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.8~rc6)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):not-affected
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
More Information

Valid XHTML 1.0 Strict

Updated: 2013-05-10 19:14:58 UTC (commit 6828)