CVE-2013-2850

Linux kernel <3.9.4 - Buffer Overflow

Title source: llm
STIX 2.1

Description

Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possibly execute arbitrary code via a long key that is not properly handled during construction of an error-response packet.

References (12)

Core 12
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1846-1
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=968036
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2013/06/01/2
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1844-1
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1845-1
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-1847-1

Scores

EPSS 0.1332
EPSS Percentile 94.2%

Details

CWE
CWE-119
Status published
Products (1)
linux/linux_kernel 3.1 - 3.2.47
Published Jun 07, 2013
Tracked Since Feb 18, 2026