CVE-2013-2224: Red Hat Enterprise Linux

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

A certain Red Hat patch for the Linux kernel 2.6.32 on Red Hat Enterprise Linux (RHEL) 6 allows local users to cause a denial of service (invalid free operation and system crash) or possibly gain privileges via a sendmsg system call with the IP_RETOPTS option, as demonstrated by hemlock.c. NOTE: this vulnerability exists because of an incorrect fix for CVE-2012-3552.

Affected products

  • Red Hat Enterprise Linux: version 6.0 only

Published 2013-07-04. Last modified 2026-06-16.