CVE-2013-3235: Infoleak
Published Apr 22, 2013
·Updated
Last updated 24 July 2024
Other sources
net/tipc/socket.c in the Linux kernel before 3.9-rc7 does not initiali ...
— Debian
Affected Software
7 affected componentsFixes available
Linux Linux kernel<=3.9
Linux Linux kernel=3.9-rc1
Linux Linux kernel=3.9-rc2
Linux Linux kernel=3.9-rc3
Linux Linux kernel=3.9-rc4
Linux Linux kernel=3.9-rc5
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
Remediation
Event History
Apr 22, 2013
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:02 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·12:57 AM
RemedyDescriptionSeverityAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2013-3235?
CVE-2013-3235 is considered a medium severity vulnerability as it allows local users to access sensitive information from kernel stack memory.
2
How do I fix CVE-2013-3235?
To fix CVE-2013-3235, upgrade to the Linux kernel version 3.9 or later.
3
What versions of Linux are affected by CVE-2013-3235?
CVE-2013-3235 affects Linux kernel versions prior to 3.9-rc7, including all 'rc' versions from 3.9-rc1 to 3.9-rc6.
4
Who can exploit CVE-2013-3235?
CVE-2013-3235 can be exploited by local users with the ability to execute crafted recvmsg or recvfrom system calls.
5
What information can be disclosed by CVE-2013-3235?
CVE-2013-3235 can potentially disclose sensitive information stored in kernel stack memory.