CVE-2013-2140

Description

The dispatch_discard_io function in drivers/block/xen-blkback/blkback.c in the Xen blkback implementation in the Linux kernel before 3.10.5 allows guest OS users to cause a denial of service (data loss) via filesystem write operations on a read-only disk that supports the (1) BLKIF_OP_DISCARD (aka discard or TRIM) or (2) SCSI UNMAP feature.

Risk Information

Base Score
5.5
MODERATE
Vector
AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.13

Associated Vulnerability

VulnerabilityOS Platform
Linux hardware enablement kernel from Raring (USN-1943-1) linux-image-3.8.0-30-generic_3.8.0-30.44~precise1_i386.debLinux
Linux hardware enablement kernel from Raring (USN-1943-1) linux-image-3.8.0-30-generic_3.8.0-30.44~precise1_amd64.debLinux
Linux hardware enablement kernel from Quantal (USN-1947-1) linux-image-3.5.0-40-generic_3.5.0-40.62~precise1_i386.debLinux
Linux hardware enablement kernel from Quantal (USN-1947-1) linux-image-3.5.0-40-generic_3.5.0-40.62~precise1_amd64.debLinux
Linux kernel (USN-2038-1) linux-image-3.2.0-57-generic_3.2.0-57.87_i386.debLinux
Linux kernel (USN-2038-1) linux-image-3.2.0-57-generic_3.2.0-57.87_amd64.debLinux
Linux kernel (USN-2038-1) linux-image-3.2.0-57-virtual_3.2.0-57.87_i386.debLinux
Linux kernel (USN-2038-1) linux-image-3.2.0-57-virtual_3.2.0-57.87_amd64.debLinux
Linux kernel (USN-2038-1) linux-image-3.2.0-57-generic-pae_3.2.0-57.87_i386.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234