CVE-2013-1959: Linux Kernel
Low severity, CVSS 3.7. EPSS: 1.2% chance of exploitation in the next 30 days.
kernel/user_namespace.c in the Linux kernel before 3.8.9 does not have appropriate capability requirements for the uid_map and gid_map files, which allows local users to gain privileges by opening a file within an unprivileged process and then modifying the file within a privileged process.
Affected products
- Linux Linux Kernel: up to and including 3.8.8; version 3.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; …
Published 2013-05-03. Last modified 2026-06-16.