CVE-2013-3301 is a denial-of-service vulnerability in the ftrace implementation of the Linux kernel before version 3.8.8, affecting Linux, Red Hat, and SUSE distributions. An attacker with CAP_SYS_ADMIN privileges can trigger a NULL pointer dereference and system crash by writing to specific ftrace files and then performing an lseek system call. With a CVSS score of 7.2, this vulnerability is considered high severity due to its local attack vector, low attack complexity, and complete impact on confidentiality, integrity, and availability. There is no evidence of active exploitation, and while an ExploitDB entry exists (EDB-38465), there are no Metasploit or Nuclei modules, and it has received minimal community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.1, < 3.2.44CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.3, < 3.4.49CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.5, < 3.8.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
6.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:* | ||
2.0CPE matchmatch criteria | cpe:2.3:o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:L/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.