UBUNTU-CVE-2013-7421
Dashboard / Vulnerabilities / UBUNTU-CVE-2013-7421
UBUNTU-CVE-2013-7421
Summary:
Details: The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.
References: https://ubuntu.com/security/CVE-2013-7421, https://lkml.org/lkml/2013/3/4/70, https://plus.google.com/+MathiasKrause/posts/PqFCo4bfrWu, https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=5d26a105b5a7, https://ubuntu.com/security/notices/USN-2513-1, https://ubuntu.com/security/notices/USN-2514-1, https://ubuntu.com/security/notices/USN-2543-1, https://ubuntu.com/security/notices/USN-2544-1, https://ubuntu.com/security/notices/USN-2545-1, https://ubuntu.com/security/notices/USN-2546-1, https://www.cve.org/CVERecord?id=CVE-2013-7421
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
