CVE-2013-4247: High severity linux kernel vulnerability
Last updated 24 July 2024
Other sources
Linux kernel built with the Common Internet File System (CONFIGCIFS) support along with a feature to access Distributed File Systems (CONFIGCIFSDFSUPCALL), is vulnerable to a memory corruption flaw caused by writing one byte past an allocated memory area. It occurs while mounting a DFS share wherein the server provides DFS referral names of certain length. The memory corruption leads to an unresponsive kernel and subsequent crash resulting in Denial of Service.
An user/program able to mount a file system could use this flaw to crash the kernel resulting in DoS.
Upstream fix: ------------- -> https://git.kernel.org/linus/1fc29bacedeabb278080e31bb9c1ecb49f143c3b
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2013/08/14/8
— Red Hat
Off-by-one error in the builduncpathtoroot function in fs/cifs/connect.c in the Linux kernel before 3.9.6 allows remote attackers to cause a denial of service (memory corruption and system crash) via a DFS share mount operation that triggers use of an unexpected DFS referral name length.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4247?
CVE-2013-4247 is classified as a medium severity vulnerability due to its potential for memory corruption.
How do I fix CVE-2013-4247?
To fix CVE-2013-4247, upgrade to the patched versions of the Linux kernel: 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.13-1.
Which systems are affected by CVE-2013-4247?
CVE-2013-4247 affects Linux kernels built with CONFIG_CIFS support and falls within the version range from 3.8 to 3.9.6.
What type of vulnerability is CVE-2013-4247?
CVE-2013-4247 is a memory corruption vulnerability caused by writing beyond an allocated memory area.
When was CVE-2013-4247 published?
CVE-2013-4247 was published on 24 July 2024.