CVE-2013-2148

low
Published 2013-06-07 ยท Modified 2026-04-29
CVSS v3
โ€”
CVSS v4 NEW
โ€”
not yet in upstream
VIR risk
2.1

Description

The fill_event_metadata function in fs/notify/fanotify/fanotify_user.c in the Linux kernel through 3.9.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a read operation on the fanotify descriptor.

Predictions

Exploit likelihood
20%
Patch ETA
โ€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker ยท View original โ†— ยท DFSG

CVE-2013-2148 NameCVE-2013-2148 DescriptionThe fill_event_metadata function in fs/notify/fanotify/fanotify_user.c in the Linux kernel through 3.9.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a read operation on the fanotify descriptor. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat,โ€ฆ

CVE-2013-2148

NameCVE-2013-2148
DescriptionThe fill_event_metadata function in fs/notify/fanotify/fanotify_user.c in the Linux kernel through 3.9.4 does not initialize a certain structure member, which allows local users to obtain sensitive information from kernel memory via a read operation on the fanotify descriptor.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2745-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)bullseye5.10.223-1fixed
bullseye (security)5.10.257-1fixed
bookworm6.1.170-3fixed
bookworm (security)6.1.172-1fixed
trixie6.12.86-1fixed
trixie (security)6.12.90-1fixed
forky7.0.9-1fixed
sid7.0.10-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcewheezy3.2.46-1+deb7u1DSA-2745-1
linuxsource(unstable)3.9.8-1low
linux-2.6sourcesqueeze(not affected)
linux-2.6source(unstable)(unfixed)low

Notes

[squeeze] - linux-2.6 <not-affected> (fanotify introduced in 2.6.36)

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
[squeeze] - linux-2.6 <not-affected> (fanotify introduced in 2.6.36)

OS impact

OSVersionStatusFixed in
suse slesaffected
debian debianbookwormfixed3.9.8-1
debian debianbullseyefixed3.9.8-1
debian debianforkyfixed3.9.8-1
debian debiansidfixed3.9.8-1
debian debiantrixiefixed3.9.8-1
linux linux-kernelaffected
linux linux-kernel3.9affected
linux linux-kernel3.9.0affected
linux linux-kernel3.9.1affected
linux linux-kernel3.9.2affected
linux linux-kernel3.9.3affected

References

CWEs

CWE-399

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.