Linux Kernel Crypto API CVE-2013-7421 Local Security Bypass Vulnerability
BID:72322
Info
Linux Kernel Crypto API CVE-2013-7421 Local Security Bypass Vulnerability
| Bugtraq ID: | 72322 |
| Class: | Design Error |
| CVE: |
CVE-2013-7421 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 27 2015 12:00AM |
| Updated: | Jul 06 2016 12:23PM |
| Credit: | Mathias Krause |
| Vulnerable: |
Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 Oracle Linux 5 Oracle Linux 0 Oracle Enterprise Linux 6.2 Oracle Enterprise Linux 6 Linux kernel 3.3.5 Linux kernel 3.3.4 Linux kernel 3.3.2 Linux kernel 3.2.13 Linux kernel 3.2.9 Linux kernel 3.2.1 Linux kernel 3.1.8 Linux kernel 3.0.5 Linux kernel 3.0.4 Linux kernel 3.0.2 Linux kernel 3.0.1 Linux kernel 2.6.39 Linux kernel 2.6.38 Linux kernel 3.2.2 Linux kernel 3.0.18 Linux kernel 3.0 Linux kernel 2.6.38.6 Linux kernel 2.6.38.4 Linux kernel 2.6.38.3 Linux kernel 2.6.38.2 |
| Not Vulnerable: | |
Discussion
Linux Kernel Crypto API CVE-2013-7421 Local Security Bypass Vulnerability
Linux kernel is prone to a local security-bypass vulnerability that may allow an attacker to bypass file permissions.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Linux kernel is prone to a local security-bypass vulnerability that may allow an attacker to bypass file permissions.
Attackers can exploit this issue to bypass certain security restrictions and perform unauthorized actions.
Exploit / POC
Linux Kernel Crypto API CVE-2013-7421 Local Security Bypass Vulnerability
Attackers can exploit this issue using readily available tools.
Attackers can exploit this issue using readily available tools.
Solution / Fix
Linux Kernel Crypto API CVE-2013-7421 Local Security Bypass Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Linux Kernel Crypto API CVE-2013-7421 Local Security Bypass Vulnerability
References:
References:
- Bug 1185469 - (CVE-2013-7421, CVE-2014-9644) CVE-2013-7421 CVE-2014-9644 Linux k (Red Hat Bugzilla)
- crypto: prefix module autoloading with "crypto-" (Linux)
- Linux kernel Homepage (kernel.org)
- Re: user ns: arbitrary module loading (Linux)
- The Crypto API in the Linux kernel before 3.19 allowed unprivileged users to loa (Mathias Krause)
- Oracle Linux Bulletin - January 2016 (Oracle)
- Ref: linuxbulletinoct2015-2719645 Oracle Linux Bulletin - October 2015 Revision (Oracle)
- Security Bulletin: Multiple Kernel vulnerabilities affect PowerKVM (Multiple CVE (IBM)