CWE
189
Advisory Published
CVE Published
Updated

CVE-2013-4345

First published: Fri Sep 13 2013(Updated: )

A flaw was found in the way ansi cprng implementation in the Linux kernel processed non-block size aligned requests. If several small requests are made that are less than the instances block size, the remainder for loop code doesn't increment rand_data_valid in the last iteration, meaning that the last bytes in the rand_data buffer gets reused on the subsequent smaller-than-a-block request for random data. Acknowledgements: Red Hat would like to thank Stephan Mueller for reporting this issue.

Credit: secalert@redhat.com

Affected SoftwareAffected VersionHow to fix
debian/linux
5.10.223-1
5.10.226-1
6.1.123-1
6.1.128-1
6.12.12-1
6.12.15-1
Linux Kernel<=3.11.4
Linux Kernel=3.0-rc1
Linux Kernel=3.0-rc2
Linux Kernel=3.0-rc3
Linux Kernel=3.0-rc4
Linux Kernel=3.0-rc5
Linux Kernel=3.0-rc6
Linux Kernel=3.0-rc7
Linux Kernel=3.0.1
Linux Kernel=3.0.2
Linux Kernel=3.0.3
Linux Kernel=3.0.4
Linux Kernel=3.0.5
Linux Kernel=3.0.6
Linux Kernel=3.0.7
Linux Kernel=3.0.8
Linux Kernel=3.0.9
Linux Kernel=3.0.10
Linux Kernel=3.0.11
Linux Kernel=3.0.12
Linux Kernel=3.0.13
Linux Kernel=3.0.14
Linux Kernel=3.0.15
Linux Kernel=3.0.16
Linux Kernel=3.0.17
Linux Kernel=3.0.18
Linux Kernel=3.0.19
Linux Kernel=3.0.20
Linux Kernel=3.0.21
Linux Kernel=3.0.22
Linux Kernel=3.0.23
Linux Kernel=3.0.24
Linux Kernel=3.0.25
Linux Kernel=3.0.26
Linux Kernel=3.0.27
Linux Kernel=3.0.28
Linux Kernel=3.0.29
Linux Kernel=3.0.30
Linux Kernel=3.0.31
Linux Kernel=3.0.32
Linux Kernel=3.0.33
Linux Kernel=3.0.34
Linux Kernel=3.0.35
Linux Kernel=3.0.36
Linux Kernel=3.0.37
Linux Kernel=3.0.38
Linux Kernel=3.0.39
Linux Kernel=3.0.40
Linux Kernel=3.0.41
Linux Kernel=3.0.42
Linux Kernel=3.0.43
Linux Kernel=3.0.44
Linux Kernel=3.0.45
Linux Kernel=3.0.46
Linux Kernel=3.0.47
Linux Kernel=3.0.48
Linux Kernel=3.0.49
Linux Kernel=3.0.50
Linux Kernel=3.0.51
Linux Kernel=3.0.52
Linux Kernel=3.0.53
Linux Kernel=3.0.54
Linux Kernel=3.0.55
Linux Kernel=3.0.56
Linux Kernel=3.0.57
Linux Kernel=3.0.58
Linux Kernel=3.0.59
Linux Kernel=3.0.60
Linux Kernel=3.0.61
Linux Kernel=3.0.62
Linux Kernel=3.0.63
Linux Kernel=3.0.64
Linux Kernel=3.0.65
Linux Kernel=3.0.66
Linux Kernel=3.0.67
Linux Kernel=3.0.68
Linux Kernel=3.1
Linux Kernel=3.1-rc1
Linux Kernel=3.1-rc2
Linux Kernel=3.1-rc3
Linux Kernel=3.1-rc4
Linux Kernel=3.1.1
Linux Kernel=3.1.2
Linux Kernel=3.1.3
Linux Kernel=3.1.4
Linux Kernel=3.1.5
Linux Kernel=3.1.6
Linux Kernel=3.1.7
Linux Kernel=3.1.8
Linux Kernel=3.1.9
Linux Kernel=3.1.10
Linux Kernel=3.2
Linux Kernel=3.2
Linux Kernel=3.2-rc2
Linux Kernel=3.2-rc3
Linux Kernel=3.2-rc4
Linux Kernel=3.2-rc5
Linux Kernel=3.2-rc6
Linux Kernel=3.2-rc7
Linux Kernel=3.2.1
Linux Kernel=3.2.2
Linux Kernel=3.2.3
Linux Kernel=3.2.4
Linux Kernel=3.2.5
Linux Kernel=3.2.6
Linux Kernel=3.2.7
Linux Kernel=3.2.8
Linux Kernel=3.2.9
Linux Kernel=3.2.10
Linux Kernel=3.2.11
Linux Kernel=3.2.12
Linux Kernel=3.2.13
Linux Kernel=3.2.14
Linux Kernel=3.2.15
Linux Kernel=3.2.16
Linux Kernel=3.2.17
Linux Kernel=3.2.18
Linux Kernel=3.2.19
Linux Kernel=3.2.20
Linux Kernel=3.2.21
Linux Kernel=3.2.22
Linux Kernel=3.2.23
Linux Kernel=3.2.24
Linux Kernel=3.2.25
Linux Kernel=3.2.26
Linux Kernel=3.2.27
Linux Kernel=3.2.28
Linux Kernel=3.2.29
Linux Kernel=3.2.30
Linux Kernel=3.3
Linux Kernel=3.3-rc1
Linux Kernel=3.3-rc2
Linux Kernel=3.3-rc3
Linux Kernel=3.3-rc4
Linux Kernel=3.3-rc5
Linux Kernel=3.3-rc6
Linux Kernel=3.3-rc7
Linux Kernel=3.3.1
Linux Kernel=3.3.2
Linux Kernel=3.3.3
Linux Kernel=3.3.4
Linux Kernel=3.3.5
Linux Kernel=3.3.6
Linux Kernel=3.3.7
Linux Kernel=3.3.8
Linux Kernel=3.4
Linux Kernel=3.4-rc1
Linux Kernel=3.4-rc2
Linux Kernel=3.4-rc3
Linux Kernel=3.4-rc3
Linux Kernel=3.4-rc4
Linux Kernel=3.4-rc5
Linux Kernel=3.4-rc6
Linux Kernel=3.4-rc7
Linux Kernel=3.4.1
Linux Kernel=3.4.2
Linux Kernel=3.4.3
Linux Kernel=3.4.4
Linux Kernel=3.4.5
Linux Kernel=3.4.6
Linux Kernel=3.4.7
Linux Kernel=3.4.8
Linux Kernel=3.4.9
Linux Kernel=3.4.10
Linux Kernel=3.4.11
Linux Kernel=3.4.12
Linux Kernel=3.4.13
Linux Kernel=3.4.14
Linux Kernel=3.4.15
Linux Kernel=3.4.16
Linux Kernel=3.4.17
Linux Kernel=3.4.18
Linux Kernel=3.4.19
Linux Kernel=3.4.20
Linux Kernel=3.4.21
Linux Kernel=3.4.22
Linux Kernel=3.4.23
Linux Kernel=3.4.24
Linux Kernel=3.4.25
Linux Kernel=3.4.26
Linux Kernel=3.4.27
Linux Kernel=3.4.28
Linux Kernel=3.4.29
Linux Kernel=3.4.30
Linux Kernel=3.4.31
Linux Kernel=3.4.32
Linux Kernel=3.5.1
Linux Kernel=3.5.2
Linux Kernel=3.5.3
Linux Kernel=3.5.4
Linux Kernel=3.5.5
Linux Kernel=3.5.6
Linux Kernel=3.5.7
Linux Kernel=3.6
Linux Kernel=3.6.1
Linux Kernel=3.6.2
Linux Kernel=3.6.3
Linux Kernel=3.6.4
Linux Kernel=3.6.5
Linux Kernel=3.6.6
Linux Kernel=3.6.7
Linux Kernel=3.6.8
Linux Kernel=3.6.9
Linux Kernel=3.6.10
Linux Kernel=3.6.11
Linux Kernel=3.7
Linux Kernel=3.7.1
Linux Kernel=3.7.2
Linux Kernel=3.7.3
Linux Kernel=3.7.4
Linux Kernel=3.7.5
Linux Kernel=3.7.6
Linux Kernel=3.7.7
Linux Kernel=3.7.8
Linux Kernel=3.7.9
Linux Kernel=3.7.10
Linux Kernel=3.8.0
Linux Kernel=3.8.1
Linux Kernel=3.8.2
Linux Kernel=3.8.3
Linux Kernel=3.8.4
Linux Kernel=3.8.5
Linux Kernel=3.8.6
Linux Kernel=3.8.7
Linux Kernel=3.8.8
Linux Kernel=3.8.9
Linux Kernel=3.8.10
Linux Kernel=3.8.11
Linux Kernel=3.8.12
Linux Kernel=3.8.13
Linux Kernel=3.9-rc1
Linux Kernel=3.9-rc2
Linux Kernel=3.9-rc3
Linux Kernel=3.9-rc4
Linux Kernel=3.9-rc5
Linux Kernel=3.9-rc6
Linux Kernel=3.9-rc7
Linux Kernel=3.9.0
Linux Kernel=3.9.1
Linux Kernel=3.9.2
Linux Kernel=3.9.3
Linux Kernel=3.9.4
Linux Kernel=3.9.5
Linux Kernel=3.9.6
Linux Kernel=3.9.7
Linux Kernel=3.9.8
Linux Kernel=3.9.9
Linux Kernel=3.9.10
Linux Kernel=3.9.11
Linux Kernel=3.10.1
Linux Kernel=3.10.2
Linux Kernel=3.10.3
Linux Kernel=3.10.4
Linux Kernel=3.10.5
Linux Kernel=3.10.6
Linux Kernel=3.10.7
Linux Kernel=3.10.8
Linux Kernel=3.10.9
Linux Kernel=3.10.10
Linux Kernel=3.10.11
Linux Kernel=3.10.12
Linux Kernel=3.11
Linux Kernel=3.11.1
Linux Kernel=3.11.2
Linux Kernel=3.11.3
Fedora=18
Fedora=19
Red Hat Enterprise Linux=5
Red Hat Enterprise Linux=6.0
Red Hat Enterprise MRG=2.0
Red Hat Enterprise MRG=2.1
Red Hat Enterprise MRG=2.2
Red Hat Enterprise MRG=2.3
Red Hat Enterprise MRG=2.4

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2013-4345?

    CVE-2013-4345 has been assigned a medium severity level due to its potential impact on the randomness generated by the kernel.

  • How do I fix CVE-2013-4345?

    To fix CVE-2013-4345, it is recommended to update to a version of the Linux kernel that is not affected, such as versions 5.10.223-1 or 6.1.119-1.

  • Which Linux kernel versions are affected by CVE-2013-4345?

    CVE-2013-4345 affects Linux kernel versions up to 3.11.4 and various release candidates like 3.0-rc1 to 3.0-rc7.

  • What type of vulnerability is CVE-2013-4345?

    CVE-2013-4345 is a vulnerability related to the improper processing of non-block size aligned requests in the ANSI CPRNG implementation.

  • Can CVE-2013-4345 lead to security risks?

    Yes, CVE-2013-4345 can lead to security risks by potentially compromising the randomness of cryptographic operations.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203