CVE-2013-0913
Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.56%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Integer overflow in drivers/gpu/drm/i915/i915_gem_execbuffer.c in the i915 driver in the Direct Rendering Manager (DRM) subsystem in the Linux kernel through 3.8.3, as used in Google Chrome OS before 25.0.1364.173 and other products, allows local users to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact via a crafted application that triggers many relocation copies, and potentially leads to a race condition.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.56% probability · 45th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- linux/linux kernel · opensuse/opensuse
- Source
- chrome-cve-admin@google.com
References
- http://git.chromium.org/gitweb/?p=chromiumos/third_party/kernel.git%3Ba=commit%3Bh=c79efdf2b7f68f985922a8272d64269ecd490477Third Party Advisory
- http://googlechromereleases.blogspot.com/2013/03/stable-channel-update-for-chrome-os_15.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlThird Party Advisory, VDB Entry
- http://openwall.com/lists/oss-security/2013/03/11/6Mailing List
- http://openwall.com/lists/oss-security/2013/03/13/9Mailing List
- http://openwall.com/lists/oss-security/2013/03/14/22Mailing List
- http://rhn.redhat.com/errata/RHSA-2013-0744.htmlThird Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1809-1Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1811-1Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1812-1Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1813-1Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1814-1Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=920471Issue Tracking
- https://code.google.com/p/chromium-os/issues/detail?id=39733Third Party Advisory
- https://gerrit.chromium.org/gerrit/45118Third Party Advisory
- https://lkml.org/lkml/2013/3/11/501Patch, Third Party Advisory
- http://git.chromium.org/gitweb/?p=chromiumos/third_party/kernel.git%3Ba=commit%3Bh=c79efdf2b7f68f985922a8272d64269ecd490477Third Party Advisory
- http://googlechromereleases.blogspot.com/2013/03/stable-channel-update-for-chrome-os_15.htmlThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2013-05/msg00018.htmlThird Party Advisory, VDB Entry
- http://lists.opensuse.org/opensuse-security-announce/2013-06/msg00005.htmlThird Party Advisory, VDB Entry
- http://openwall.com/lists/oss-security/2013/03/11/6Mailing List
- http://openwall.com/lists/oss-security/2013/03/13/9Mailing List
- http://openwall.com/lists/oss-security/2013/03/14/22Mailing List
- http://rhn.redhat.com/errata/RHSA-2013-0744.htmlThird Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1809-1Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1811-1Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1812-1Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1813-1Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-1814-1Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.