Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 458422 (CVE-2013-0309) - Kernel : Multiple vulnerabilities (CVE-2013-{0309,0310,0311})
Summary: Kernel : Multiple vulnerabilities (CVE-2013-{0309,0310,0311})
Alias: CVE-2013-0309
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Kernel Security
Depends on:
Reported: 2013-02-20 09:02 UTC by Agostino Sarubbo
Modified: 2018-04-04 18:32 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2013-02-20 09:02:45 UTC


If a single descriptor crosses a region, the second chunk length should
be decremented by size translated so far, instead it includes the full
descriptor length. A privileged guest user could use this flaw to crash
the host or, potentially, corrupt host memory.

Upstream fix:;a=commitdiff;h=bd97120fc3d1a11f3124c7c9ba1d91f51829eb85



The skb argument to cipso_v4_validate() is NULL when called via the
setsockopt() syscall. An local user able to set CIPSO IP options on the
socket could use this flaw to crash the system.

Upstream fix:;a=commit;h=89d7ae34cdda4195809a5a987f697a517a2a3177



Most VM places are using pmd_none but a few are still using pmd_present.
The meaning is about the same for the pmd. However pmd_present would
return the wrong value on PROT_NONE ranges. When the code using
pmd_present gets a false negative, the kernel will crash.

An unprivileged local user could use this flaw to crash the system.

Upstream fix:;a=commit;h=027ef6c8

Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2013-03-04 23:23:28 UTC
CVE-2013-0311 (
  The translate_desc function in drivers/vhost/vhost.c in the Linux kernel
  before 3.7 does not properly handle cross-region descriptors, which allows
  guest OS users to obtain host OS privileges by leveraging KVM guest OS

CVE-2013-0310 (
  The cipso_v4_validate function in net/ipv4/cipso_ipv4.c in the Linux kernel
  before 3.4.8 allows local users to cause a denial of service (NULL pointer
  dereference and system crash) or possibly have unspecified other impact via
  an IPOPT_CIPSO IP_OPTIONS setsockopt system call.

CVE-2013-0309 (
  arch/x86/include/asm/pgtable.h in the Linux kernel before 3.6.2, when
  transparent huge pages are used, does not properly support PROT_NONE memory
  regions, which allows local users to cause a denial of service (system
  crash) via a crafted application.
Comment 2 Aaron Bauman (RETIRED) gentoo-dev 2018-04-04 18:32:06 UTC
There are no longer any 2.x or <3.7 kernels available in the repository with the exception of sys-kernel/xbox-sources which is unsupported by security.