Back

HIGH

Kernel: net: ipvs: stack buffer overflow

Published Nov 19, 2013

Description

Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability for (1) a getsockopt system call, related to the do_ip_vs_get_ctl function, or (2) a setsockopt system call, related to the do_ip_vs_set_ctl function.

Affected products

Remediation

Red Hat statement

The Red Hat Security Response Team does not consider this issue to be a security flaw. Please see http://seclists.org/oss-sec/2014/q1/174 for CVE REJECT request and further information.

Metrics

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Nov 19, 2013
Updated Aug 6, 2024
Reserved Jun 12, 2013
NVD
Status Modified
Modified Jun 16, 2026
Red Hat
Severity n/a
Public date Nov 11, 2013