Skip to main content

Linux Kernel Array Bounds Checking Vulnerability

Last Update Date: 16 May 2013 18:33 Release Date: 16 May 2013 3741 Views

RISK: Medium Risk

TYPE: Operating Systems - Linux

TYPE: Linux

A vulnerability has been identified in the Linux Kernel. A local user can obtain elevated privileges on the target system.

 

On systems compiled with PERF_EVENTS support, a local user can supply a specially crafted perf_event_open() call to execute arbitrary code on the target system with root privileges.

 

The vulnerability resides in the perf_swevent_init() function in 'kernel/events/core.c'.


Impact

  • Elevation of Privilege

System / Technologies affected

  • 2.6.37 to 3.8.9

Solutions

Before installation of the software, please visit the software manufacturer web-site for more details.

  • The vendor has issued a fix (3.8.9rc8).

Vulnerability Identifier


Source


Related Link