CVE-2013-4348: High severity linux kernel vulnerability
A flaw was found in the way ip packets with ihl of zero were processed in the skbflowdissect() function in the Linux kernel.
A remote attacker could use this flaw to cause inifinite loop in the kernel.
Acknowledgements:
This issue was found by Jason Wang of Red Hat.
Other sources
The skbflowdissect function in net/core/flowdissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2013-4348?
CVE-2013-4348 is considered a medium severity vulnerability due to its potential to cause an infinite loop in the Linux kernel.
How do I fix CVE-2013-4348?
To fix CVE-2013-4348, update the Linux kernel to a version that is not affected, such as any version beyond the specified vulnerable ranges.
Which Linux kernel versions are affected by CVE-2013-4348?
CVE-2013-4348 affects Linux kernel versions from 3.2 to 3.12.1, including specific versions of Ubuntu Linux 12.04 and 13.10.
Can CVE-2013-4348 be exploited remotely?
Yes, CVE-2013-4348 can be exploited remotely, allowing an attacker to trigger denial of service conditions.
What should I do if my system is vulnerable to CVE-2013-4348?
If your system is vulnerable to CVE-2013-4348, immediately upgrade to a fixed kernel version to mitigate the risk.