CVE-2013-0313
Published: 21 February 2013
The evm_update_evmxattr function in security/integrity/evm/evm_crypto.c in the Linux kernel before 3.7.5, when the Extended Verification Module (EVM) is enabled, allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via an attempted removexattr operation on an inode of a sockfs filesystem.
From the Ubuntu security team
A flaw was discovered in the Extended Verification Module (EVM) of the Linux kernel. An unprivileged local user code exploit this flaw to cause a denial of service (system crash).
Priority
Status
Notes
Author | Note |
---|---|
henrix | EVM wasn't merged before 3.2, thus not applicable before Precise |
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2013-0313
- http://www.openwall.com/lists/oss-security/2013/02/20
- https://ubuntu.com/security/notices/USN-1767-1
- https://ubuntu.com/security/notices/USN-1768-1
- https://ubuntu.com/security/notices/USN-1769-1
- https://ubuntu.com/security/notices/USN-1781-1
- https://ubuntu.com/security/notices/USN-1774-1
- NVD
- Launchpad
- Debian