SB2013032204 - NULL pointer dereference in Linux kernel



SB2013032204 - NULL pointer dereference in Linux kernel

Published: March 22, 2013 Updated: August 11, 2020

Security Bulletin ID SB2013032204
Severity
Medium
Patch available
NO
Number of vulnerabilities 1
Exploitation vector Local access
Highest impact Denial of service

Breakdown by Severity

Medium 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) NULL pointer dereference (CVE-ID: CVE-2013-1792)

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trigger denial of service conditions via crafted keyctl system calls that trigger keyring operations in simultaneous threads.


Remediation

Cybersecurity Help is not aware of any official remediation provided by the vendor.