UBUNTU-CVE-2013-4254
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-4254
UBUNTU-CVE-2013-4254
Summary:
Details: The validate_event function in arch/arm/kernel/perf_event.c in the Linux kernel before 3.10.8 on the ARM platform allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by adding a hardware event to an event group led by a software event.
References: https://ubuntu.com/security/CVE-2013-4254, http://www.openwall.com/lists/oss-security/2013/08/16/5, http://www.arm.linux.org.uk/developer/patches/viewpatch.php?id=7809/1, https://ubuntu.com/security/notices/USN-1968-1, https://ubuntu.com/security/notices/USN-1969-1, https://ubuntu.com/security/notices/USN-1970-1, https://ubuntu.com/security/notices/USN-1971-1, https://ubuntu.com/security/notices/USN-1972-1, https://ubuntu.com/security/notices/USN-1973-1, https://ubuntu.com/security/notices/USN-1974-1, https://ubuntu.com/security/notices/USN-1975-1, https://www.cve.org/CVERecord?id=CVE-2013-4254
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
