CVE-2013-4254: Null Pointer Dereference

Published Aug 20, 2013
·
Updated

Last updated 24 July 2024

Other sources

Linux kernel built for the ARM(CONFIGARM/CONFIGARM64) platforms along with the hardware performance counter support(CONFIGHWPERFEVENTS) is vulnerable to a NULL pointer dereference flaw. This could lead to the kernel crash resulting in DoS or potential privilege escalation to gain root privileges by a non-root user.

An unprivileged user/program could use this flaw to crash the kernel resulting in DoS or potential privilege escalation to gain root access to a machine.

Upstream fix: ------------- -> https://lkml.org/lkml/2013/8/7/259

Reference: ---------- -> http://seclists.org/oss-sec/2013/q3/381

Red Hat

The validateevent function in arch/arm/kernel/perfevent.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by adding a hardware event to an event group led by a software event.

Launchpad

Affected Software

9 affected componentsFixes available
Linux Linux kernel<=3.10.7
Linux Linux kernel=3.10.0
Linux Linux kernel=3.10.1
Linux Linux kernel=3.10.2
Linux Linux kernel=3.10.3
Linux Linux kernel=3.10.4
Linux Linux kernel=3.10.5
Linux Linux kernel=3.10.6
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1

Event History

Aug 20, 2013
Data Sourced
via Red Hat·09:34 AM
DescriptionSeverityAffected Software
Aug 25, 2013
CVE Published
via MITRE·01:00 AM
Data Sourced
via MITRE·01:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:02 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:00 AM
RemedyDescriptionSeverityAffected Software
Apr 24, 2025
Data Sourced
via Debian·02:07 AM
DescriptionAffected Software

Frequently Asked Questions

1

What is the severity of CVE-2013-4254?

CVE-2013-4254 has a severity rating that indicates it may lead to a denial of service or privilege escalation due to potential kernel crashes.

2

How do I fix CVE-2013-4254?

To mitigate CVE-2013-4254, upgrade to a patched version of the Linux kernel, specifically versions such as 5.10.223-1, 6.1.123-1, or later.

3

Which Linux kernel versions are affected by CVE-2013-4254?

CVE-2013-4254 affects Linux kernel versions 3.10.0 to 3.10.7 on ARM and ARM64 platforms.

4

What are the potential consequences of CVE-2013-4254?

The consequences of CVE-2013-4254 may include system crashes, resulting in denial of service and potential for unauthorized privilege escalation.

5

Is CVE-2013-4254 specific to any particular hardware?

CVE-2013-4254 is specifically related to the ARM and ARM64 hardware architectures due to their performance counter support.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203