← Back

CVE-2013-1958

nvd nist
Published: Apr 24, 2013Modified: Apr 29, 2026

JSON object

Loading...
1.9
Vector
AV:L/AC:M/Au:N/C:N/I:P/A:N
Exploitability: 3.4 / Impact: 2.9
Source: NVD

Description

The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.8.6 does not properly enforce capability requirements for controlling the PID value associated with a UNIX domain socket, which allows local users to bypass intended access restrictions by leveraging the time interval during which a user namespace has been created but a PID namespace has not been created.

Affected (6)

Products: Linux: Linux Kernel
1 product
Linux Kernel
Configuration A
6 vulnerable
Vulnerable SoftwareAffected Versions
Linux
Up to 3.8.5
Version 3.8.0
Version 3.8.1
Version 3.8.2
Version 3.8.3
Version 3.8.4

Related CWEs

Timeline

No history available yet.