CVE-2013-1819
Publication date 6 March 2013
Last updated 24 July 2024
Ubuntu priority
The _xfs_buf_find function in fs/xfs/xfs_buf.c in the Linux kernel before 3.7.6 does not validate block numbers, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the ability to mount an XFS filesystem containing a metadata inode with an invalid extent map.
From the Ubuntu Security Team
A failure to validate block numbers was discovered in the Linux kernel's implementation of the XFS filesystem. A local user can cause a denial of service (system crash) if they can mount, or cause to be mounted a corrupted or special crafted XFS filesystem.
Status
Package | Ubuntu Release | Status |
---|---|---|
linux | 14.04 LTS trusty |
Not affected
|
linux-2.6 | 14.04 LTS trusty | Not in release |
linux-armadaxp | 14.04 LTS trusty | Not in release |
linux-ec2 | 14.04 LTS trusty | Not in release |
linux-flo | 14.04 LTS trusty | Ignored end of life, was needed |
linux-fsl-imx51 | 14.04 LTS trusty | Not in release |
linux-goldfish | 14.04 LTS trusty | Ignored end of life, was needed |
linux-grouper | 14.04 LTS trusty | Not in release |
linux-linaro-omap | 14.04 LTS trusty | Not in release |
linux-linaro-shared | 14.04 LTS trusty | Not in release |
linux-linaro-vexpress | 14.04 LTS trusty | Not in release |
linux-lts-backport-maverick | 14.04 LTS trusty | Not in release |
linux-lts-backport-oneiric | 14.04 LTS trusty | Not in release |
linux-lts-quantal | 14.04 LTS trusty | Not in release |
linux-lts-raring | 14.04 LTS trusty | Not in release |
linux-lts-trusty | 14.04 LTS trusty | Not in release |
linux-maguro | 14.04 LTS trusty | Not in release |
linux-mako | 14.04 LTS trusty | Ignored end of life, was needed |
linux-manta | 14.04 LTS trusty | Ignored end of life, was needed |
linux-mvl-dove | 14.04 LTS trusty | Not in release |
linux-qcm-msm | 14.04 LTS trusty | Not in release |
linux-ti-omap4 | 14.04 LTS trusty | Not in release |
Notes
henrix
This CVE has minor impact as it requires root privileges to mount a corrupted image. Also, it is too risky to backport the fix to older kernels (Precise, in this case).
jjohansen
precise_linux and precise_linux-lts-quantal ignored (was in USN-1968-1/3.2.0-54.82 reverted minor priority CVE with high risk of regression in backport) precise_linux-armadaxp ignored due to high risk of regression in backport
References
Related Ubuntu Security Notices (USN)
- USN-1968-1
- Linux kernel vulnerabilities
- 27 September 2013
- USN-1969-1
- Linux kernel (OMAP4) vulnerabilities
- 27 September 2013
- USN-1973-1
- Linux kernel (OMAP4) vulnerabilities
- 27 September 2013
- USN-1970-1
- Linux kernel (Quantal HWE) vulnerabilities
- 27 September 2013
- USN-1975-1
- Linux kernel (OMAP4) vulnerabilities
- 27 September 2013
- USN-1972-1
- Linux kernel vulnerabilities
- 27 September 2013