CVE-2013-2128: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The tcp_read_sock function in net/ipv4/tcp.c in the Linux kernel before 2.6.34 does not properly manage skb consumption, which allows local users to cause a denial of service (system crash) via a crafted splice system call for a TCP socket.
Affected products
- Linux Linux Kernel: before 2.6.34 (fixed in 2.6.34)
Published 2013-06-07. Last modified 2026-06-16.