CVE-2013-1772

Priority
Medium
Description
The log_prefix function in kernel/printk.c in the Linux kernel 3.x before
3.4.33 does not properly remove a prefix string from a syslog header, which
allows local users to cause a denial of service (buffer overflow and system
crash) by leveraging /dev/kmsg write access and triggering a
call_console_drivers function call.
Ubuntu-Description
A buffer overflow was discovered in the Linux kernel's /dev/kmesg device. A
local user could exploit this flaw to cause a denial of service (system
crash).
References
Bugs
Notes
mdeslaur> /dev/kmsg is root-writable only
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):released (3.2.0-1615.23)
Ubuntu 12.10 (Quantal Quetzal):not-affected (3.5.0-1600.1)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):not-affected
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (abandoned)
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):pending (3.5.0-1.1~precise1)
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Patches:
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Source: linux (LP Ubuntu Debian)
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):not-affected
Ubuntu 12.04 LTS (Precise Pangolin):released (3.2.0-39.62)
Ubuntu 12.10 (Quantal Quetzal):pending (3.5.0-1.1)
Ubuntu 13.04 (Raring Ringtail):not-affected (3.7.0-0.1)
Ubuntu 13.10 (Saucy Salamander):not-affected (3.7.0-0.1)
Patches:
Introduced by 162a7e7500f9664636e649ba59defe541b7c2c60Fixed by 7ff9554bb578ba02166071d2d487b7fc7d860d62
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):released (3.2.0-1427.36)
Ubuntu 12.10 (Quantal Quetzal):pending (3.5.0-207.13)
Ubuntu 13.04 (Raring Ringtail):not-affected (3.5.0-207.13)
Ubuntu 13.10 (Saucy Salamander):not-affected (3.5.0-207.13)
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):ignored (abandoned)
Ubuntu 12.10 (Quantal Quetzal):ignored (abandoned)
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):ignored (reached end-of-life, does not affect buildd)
Ubuntu 12.04 LTS (Precise Pangolin):DNE
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
Package
Upstream:released (3.5~rc1)
Ubuntu 10.04 LTS (Lucid Lynx):DNE
Ubuntu 12.04 LTS (Precise Pangolin):not-affected
Ubuntu 12.10 (Quantal Quetzal):DNE
Ubuntu 13.04 (Raring Ringtail):DNE
Ubuntu 13.10 (Saucy Salamander):DNE
More Information

Valid XHTML 1.0 Strict

Updated: 2013-05-22 14:15:20 UTC (commit 6866)