CVE Vulnerabilities

CVE-2013-1958

Published: Apr 24, 2013 | Modified: Apr 11, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
1.9 LOW
AV:L/AC:M/Au:N/C:N/I:P/A:N
RedHat/V2
RedHat/V3
Ubuntu
MEDIUM
root.io logo minimus.io logo echo.ai logo

The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.8.6 does not properly enforce capability requirements for controlling the PID value associated with a UNIX domain socket, which allows local users to bypass intended access restrictions by leveraging the time interval during which a user namespace has been created but a PID namespace has not been created.

Affected Software

NameVendorStart VersionEnd Version
Linux_kernelLinux*3.8.5 (including)
Linux_kernelLinux3.8.0 (including)3.8.0 (including)
Linux_kernelLinux3.8.1 (including)3.8.1 (including)
Linux_kernelLinux3.8.2 (including)3.8.2 (including)
Linux_kernelLinux3.8.3 (including)3.8.3 (including)
Linux_kernelLinux3.8.4 (including)3.8.4 (including)
LinuxUbuntuupstream*
Linux-armadaxpUbuntuupstream*
Linux-ec2Ubuntuupstream*
Linux-fsl-imx51Ubuntulucid*
Linux-fsl-imx51Ubuntuupstream*
Linux-linaro-omapUbuntudevel*
Linux-linaro-omapUbuntuoneiric*
Linux-linaro-omapUbuntuprecise*
Linux-linaro-omapUbuntuquantal*
Linux-linaro-omapUbuntuupstream*
Linux-linaro-sharedUbuntudevel*
Linux-linaro-sharedUbuntuoneiric*
Linux-linaro-sharedUbuntuprecise*
Linux-linaro-sharedUbuntuquantal*
Linux-linaro-sharedUbuntuupstream*
Linux-linaro-vexpressUbuntudevel*
Linux-linaro-vexpressUbuntuoneiric*
Linux-linaro-vexpressUbuntuprecise*
Linux-linaro-vexpressUbuntuquantal*
Linux-linaro-vexpressUbuntuupstream*
Linux-lts-backport-maverickUbuntulucid*
Linux-lts-backport-maverickUbuntuupstream*
Linux-lts-backport-oneiricUbuntuupstream*
Linux-lts-quantalUbuntuupstream*
Linux-mvl-doveUbuntulucid*
Linux-mvl-doveUbuntuupstream*
Linux-qcm-msmUbuntudevel*
Linux-qcm-msmUbuntulucid*
Linux-qcm-msmUbuntuoneiric*
Linux-qcm-msmUbuntuprecise*
Linux-qcm-msmUbuntuquantal*
Linux-qcm-msmUbuntuupstream*
Linux-ti-omap4Ubuntuupstream*

References