#VU42963 NULL pointer dereference in Linux kernel - CVE-2013-1792

 

#VU42963 NULL pointer dereference in Linux kernel - CVE-2013-1792

Published: March 22, 2013 / Updated: August 11, 2020


Vulnerability identifier: #VU42963
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2013-1792
CWE-ID: CWE-476
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Linux kernel
Software vendor:
Linux Foundation

Description

The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.

The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trigger denial of service conditions via crafted keyctl system calls that trigger keyring operations in simultaneous threads.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links