• Tenable
  • CVEs
  • Settings
    Links
    Tenable.io Tenable Community & Support Tenable University
    Severity
    Theme
  • Tenable
  • Links
  • Tenable.io
  • Tenable Community & Support
  • Tenable University
  • Settings
  • Severity
  • Theme
  • Newest
  • Updated
  • Search
  • Newest
  • Updated
  • Search
  1. CVEs
  2. CVE-2013-4587
  1. CVEs

CVE-2013-4587

high
  • Information
  • CPEs
  • Plugins

Description

Array index error in the kvm_vm_ioctl_create_vcpu function in virt/kvm/kvm_main.c in the KVM subsystem in the Linux kernel through 3.12.5 allows local users to gain privileges via a large id value.

References

https://github.com/torvalds/linux/commit/338c7dbadd2671189cec7faf64c84d01071b3f96

https://bugzilla.redhat.com/show_bug.cgi?id=1030986

http://www.openwall.com/lists/oss-security/2013/12/12/12

https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.54

http://lists.opensuse.org/opensuse-updates/2014-02/msg00045.html

http://www.ubuntu.com/usn/USN-2110-1

http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00002.html

http://www.ubuntu.com/usn/USN-2109-1

http://www.ubuntu.com/usn/USN-2113-1

http://www.ubuntu.com/usn/USN-2117-1

http://lists.opensuse.org/opensuse-security-announce/2014-02/msg00003.html

http://www.ubuntu.com/usn/USN-2138-1

http://www.ubuntu.com/usn/USN-2136-1

http://www.ubuntu.com/usn/USN-2129-1

http://www.ubuntu.com/usn/USN-2128-1

http://www.ubuntu.com/usn/USN-2139-1

http://www.ubuntu.com/usn/USN-2141-1

http://www.ubuntu.com/usn/USN-2135-1

http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=338c7dbadd2671189cec7faf64c84d01071b3f96

Details

Source: MITRE

Published: 2013-12-14

Updated: 2023-02-13

Type: CWE-20

Risk Information

CVSS v2

Base Score: 7.2

Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Impact Score: 10

Exploitability Score: 3.9

Severity: HIGH

  • Tenable.com
  • Community & Support
  • Documentation
  • Education
  • © 2023 Tenable®, Inc. All Rights Reserved
  • Privacy Policy
  • Legal
  • 508 Compliance