CVE-2013-7446

NameCVE-2013-7446
DescriptionUse-after-free vulnerability in net/unix/af_unix.c in the Linux kernel before 4.3.3 allows local users to bypass intended AF_UNIX socket permissions or cause a denial of service (panic) via crafted epoll_ctl calls.
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDLA-360-1, DSA-3426-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)bullseye5.10.223-1fixed
bullseye (security)5.10.226-1fixed
bookworm6.1.106-3fixed
bookworm (security)6.1.112-1fixed
trixie6.10.11-1fixed
sid6.11.2-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcewheezy3.2.73-2+deb7u1DSA-3426-1
linuxsourcejessie3.16.7-ckt20-1+deb8u1DSA-3426-1
linuxsource(unstable)4.2.6-2
linux-2.6sourcesqueeze2.6.32-48squeeze17DLA-360-1
linux-2.6source(unstable)(unfixed)

Notes

https://bugzilla.redhat.com/show_bug.cgi?id=1273845
https://groups.google.com/forum/#!topic/syzkaller/3twDUI4Cpm8
https://www.openwall.com/lists/oss-security/2015/11/18/9
Introduced by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ec0d215f9420564fc8286dcf93d2d068bb53a07e (v2.6.26-rc9)
Fixed by: https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=7d267278a9ece963d77eefec61630223fce08c6c (v4.4-rc4)

Search for package or bug name: Reporting problems