CVE-2013-7446 is a use-after-free vulnerability in the Linux kernel's AF_UNIX socket implementation (net/unix/af_unix.c) affecting versions prior to 4.3.3. This flaw allows local attackers to bypass socket permissions or trigger a denial of service (system panic) through specially crafted epoll_ctl calls. Rated Medium (CVSS 5.3), exploitation requires local access and high attack complexity, primarily impacting system availability and potentially integrity. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage for this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.3.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.