CVE Database
/

CVE-2013-4470

Back to search

CVE-2013-4470

Published: Nov 4, 2013

Modified: Aug 6, 2024

PUBLISHED

Description

The Linux kernel before 3.12, when UDP Fragmentation Offload (UFO) is enabled, does not properly initialize certain data structures, which allows local users to cause a denial of service (memory corruption and system crash) or possibly gain privileges via a crafted application that uses the UDP_CORK option in a setsockopt system call and sends both short and long packets, related to the ip_ufo_append_data function in net/ipv4/ip_output.c and the ip6_ufo_append_data function in net/ipv6/ip6_output.c.

VendorProductVersions

n/a

n/a

affected
n/a

References

USN-2043-1
vendor-advisory
x_refsource_UBUNTU
USN-2073-1
vendor-advisory
x_refsource_UBUNTU
USN-2040-1
vendor-advisory
x_refsource_UBUNTU
USN-2069-1
vendor-advisory
x_refsource_UBUNTU
USN-2044-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2013:1801
vendor-advisory
x_refsource_REDHAT
USN-2066-1
vendor-advisory
x_refsource_UBUNTU
SUSE-SU-2014:0459
vendor-advisory
x_refsource_SUSE
USN-2049-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2014:0284
vendor-advisory
x_refsource_REDHAT
63359
vdb-entry
x_refsource_BID
USN-2050-1
vendor-advisory
x_refsource_UBUNTU
USN-2042-1
vendor-advisory
x_refsource_UBUNTU
RHSA-2014:0100
vendor-advisory
x_refsource_REDHAT
USN-2067-1
vendor-advisory
x_refsource_UBUNTU
USN-2046-1
vendor-advisory
x_refsource_UBUNTU

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now