CVE-2013-2094: Linux Kernel Privilege Escalation Vulnerability
A flaw was found in the way index into perfsweventenabled array was sanitized.
A local unprivileged user can use this flaw to increase their privileges on the system.
Introduced by: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b0a873ebbf87bf38bf70b5e39a7cadc96099fa13
Upstream fix: http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=8176cced706b5e5d15887584150764894e94e02f
References: http://lkml.indiana.edu/hypermail/linux/kernel/1304.1/03652.html https://news.ycombinator.com/item?id=5703758 http://packetstormsecurity.com/files/121616/semtex.c
Other sources
Linux kernel fails to check all 64 bits of attr.config passed by user space, resulting to out-of-bounds access of the perfsweventenabled array in swperfeventdestroy(). Explotation allows for privilege escalation.
— CISA
The perfsweventinit function in kernel/events/core.c in the Linux kernel before 3.8.9 uses an incorrect integer data type, which allows local users to gain privileges via a crafted perfeventopen system call.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.234-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.129-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.1.135-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.25-1 - Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 6.12.27-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 3.8.9 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch 8176cced706b5e5d15887584150764894e94e02f - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch b0a873ebbf87bf38bf70b5e39a7cadc96099fa13
Event History
Frequently Asked Questions
What is the severity of CVE-2013-2094?
CVE-2013-2094 has a moderate severity level as it allows local unprivileged users to potentially escalate their privileges.
How do I fix CVE-2013-2094?
To fix CVE-2013-2094, upgrade to a patched version of the Linux kernel listed in the vulnerability details.
What systems are affected by CVE-2013-2094?
CVE-2013-2094 affects multiple versions of the Linux kernel from versions prior to 3.9 and specific versions up to 6.12.10.
Who discovered CVE-2013-2094?
CVE-2013-2094 was discovered in the Linux kernel by the open-source community during routine audits.
Is there a workaround for CVE-2013-2094?
There are no specific workarounds for CVE-2013-2094; updating the kernel is the recommended action.