CVE-2013-2239
Estado: ModificadaMedia (4.7)—
vzkernel before 042stab080.2 in the OpenVZ modification for the Linux kernel 2.6.32 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via (1) a crafted ploop driver ioctl call, related to the ploop_getdevice_ioc function in drivers/block/ploop/dev.c, or (2) a crafted quotactl system call, related to the compat_quotactl function in fs/quota/quota.c.
CVSS
- Versión: 2.0
- Vector: AV:L/AC:M/Au:N/C:C/I:N/A:N
- Puntuación base: 4.7
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.35%
- Percentil entre todas las CVEs puntuadas: 27
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-264
Referencias
- http://openwall.com/lists/oss-security/2013/07/04/9
- http://wiki.openvz.org/Download/kernel/rhel6-testing/042stab080.2
- http://www.debian.org/security/2013/dsa-2766
- https://bugs.gentoo.org/show_bug.cgi?id=475762
- https://security-tracker.debian.org/tracker/CVE-2013-2239
- http://openwall.com/lists/oss-security/2013/07/04/9
- http://wiki.openvz.org/Download/kernel/rhel6-testing/042stab080.2
- http://www.debian.org/security/2013/dsa-2766
- https://bugs.gentoo.org/show_bug.cgi?id=475762
- https://security-tracker.debian.org/tracker/CVE-2013-2239
JSON original (NVD)
Mostrar
{
"id": "CVE-2013-2239",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 4.7,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:M/Au:N/C:C/I:N/A:N",
"authentication": "NONE",
"integrityImpact": "NONE",
"accessComplexity": "MEDIUM",
"availabilityImpact": "NONE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 6.9,
"baseSeverity": "MEDIUM",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.4,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "secalert@redhat.com",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2013-11-12T14:35:11.353",
"references": [
{
"url": "http://openwall.com/lists/oss-security/2013/07/04/9",
"source": "secalert@redhat.com"
},
{
"url": "http://wiki.openvz.org/Download/kernel/rhel6-testing/042stab080.2",
"source": "secalert@redhat.com"
},
{
"url": "http://www.debian.org/security/2013/dsa-2766",
"source": "secalert@redhat.com"
},
{
"url": "https://bugs.gentoo.org/show_bug.cgi?id=475762",
"source": "secalert@redhat.com"
},
{
"url": "https://security-tracker.debian.org/tracker/CVE-2013-2239",
"source": "secalert@redhat.com"
},
{
"url": "http://openwall.com/lists/oss-security/2013/07/04/9",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://wiki.openvz.org/Download/kernel/rhel6-testing/042stab080.2",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.debian.org/security/2013/dsa-2766",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://bugs.gentoo.org/show_bug.cgi?id=475762",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://security-tracker.debian.org/tracker/CVE-2013-2239",
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "vzkernel before 042stab080.2 in the OpenVZ modification for the Linux kernel 2.6.32 does not initialize certain length variables, which allows local users to obtain sensitive information from kernel stack memory via (1) a crafted ploop driver ioctl call, related to the ploop_getdevice_ioc function in drivers/block/ploop/dev.c, or (2) a crafted quotactl system call, related to the compat_quotactl function in fs/quota/quota.c."
},
{
"lang": "es",
"value": "vzkernel anterior a versión 042stab080.2 en la modificación de OpenVZ para el kernel de Linux versión 2.6.32, no inicializa determinadas variables de longitud, lo que permite a usuarios locales obtener información confidencial de la memoria de la pila del kernel por medio de (1) una llamada ioctl del controlador ploop diseñada, relacionado con la función ploop_getdevice_ioc en el archivo drivers/block/ploop/dev.c, o (2) una llamada de sistema quotactl diseñada, relacionada con la función compat_quotactl en fs/quota/quota.c."
}
],
"lastModified": "2026-06-16T23:53:00.073",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:o:openvz:vzkernel:2.6.32:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "C297A326-053E-4AC0-9A82-18C75CE81808"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "secalert@redhat.com"
}