CVE-2013-3076
Last modified
CVE-2013-3076 is a vulnerability of currently unknown severity. The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg function in crypto/algif_hash.c and the skcipher_recvmsg function in crypto/algif_skcipher.c.. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
The crypto API in the Linux kernel through 3.9-rc8 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via a crafted recvmsg or recvfrom system call, related to the hash_recvmsg function in crypto/algif_hash.c and the skcipher_recvmsg function in crypto/algif_skcipher.c.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Linux | Linux Kernel | <= 3.9 | Rc7 |
| Linux | Linux Kernel | 3.9 | Rc1 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2013-3076?
How severe is CVE-2013-3076?
How do I fix CVE-2013-3076?
Are you affected by CVE-2013-3076?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
