Vulnerability Name: | CVE-2013-2140 (CCN-84804) | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Assigned: | 2013-06-05 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Published: | 2013-06-05 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Updated: | 2023-02-13 | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Summary: | Linux Kernel could allow a local attacker to bypass security restrictions, caused by the failure to properly check for disk write permissions by the dispatch_discard_io() function. An attacker could exploit this vulnerability to write to read only disk. | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v3 Severity: | 4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
CVSS v2 Severity: | 3.8 Low (CVSS v2 Vector: AV:A/AC:M/Au:S/C:N/I:P/A:P) 2.8 Low (Temporal CVSS v2 Vector: AV:A/AC:M/Au:S/C:N/I:P/A:P/E:U/RL:OF/RC:C)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:P/A:N/E:U/RL:OF/RC:C)
| ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerability Consequences: | Bypass Security | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2013-2140 Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: oss-sec Mailing List: Wed, 5 Jun 2013 xen/blkback: Check device permissions before allowing OP_DISCARD Source: CCN Type: SA53666 Linux Kernel "dispatch_discard_io()" RO Disk Manipulation Security Issue Source: CCN Type: The Linux Kernel Archives Web site The Linux Kernel Archives Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: BID-60414 Linux Kernel 'dispatch_discard_io()' Function Security Bypass Vulnerability Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: Red Hat Bugzilla Bug 971146 (CVE-2013-2140) CVE-2013-2140 kernel: xen: blkback: insufficient permission checks for BLKIF_OP_DISCARD Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: XF Type: UNKNOWN linux-kernel-cve20132140-sec-bypass(84804) Source: secalert@redhat.com Type: Exploit, Patch secalert@redhat.com | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Vulnerable Configuration: | Configuration CCN 1:![]() | ||||||||||||||||||||||||||||||||||||||||||||||||||||||||
Oval Definitions | |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
| |||||||||||||||||||||||||||||||||||||||||||||||||||||||||
BACK |