CVE-2013-1797

Advisory lineage Upstream: 0 Downstream: 7
Modified
Published: 22 Mar 2013, 10:00
Last modified:06 Aug 2024, 15:13

Vulnerability Summary

Overall Risk (default)
medium
27/100
CVSS Score
6.8 MEDIUM
v2.0 (nvd)
EPSS Score
0.62% LOW
1% probability +0.16%
KEV
Not listed
Ransomware
No reports
Public exploits
None found
Dark Web
Not detected

Timeline

22 Mar 2013, 10:00
Published
Vulnerability first disclosed
06 Aug 2024, 15:13
Last Modified
Vulnerability information updated

Description

Use-after-free vulnerability in arch/x86/kvm/x86.c in the Linux kernel through 3.8.4 allows guest OS users to cause a denial of service (host OS memory corruption) or possibly have unspecified other impact via a crafted application that triggers use of a guest physical address (GPA) in (1) movable or (2) removable memory during an MSR_KVM_SYSTEM_TIME kvm_set_msr_common operation.

CVSS Metrics

  • v2.0MEDIUMScore: 6.8AV:A/AC:H/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 0.62% Percentile: 70%

Techniques & Countermeasures

  • CWE-399Resource Management Errors

    Weaknesses in this category are related to improper management of system resources.

Affected Systems

  • linuxlinux_kernel

    ≤ 3.8.4 | 3.8.0 | 3.8.1 | 3.8.2 | 3.8.3

References (16)