CVE-2013-3301: Linux Kernel
High severity, CVSS 7.2. EPSS: 1% chance of exploitation in the next 30 days.
The ftrace implementation in the Linux kernel before 3.8.8 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact by leveraging the CAP_SYS_ADMIN capability for write access to the (1) set_ftrace_pid or (2) set_graph_function file, and then making an lseek system call.
Affected products
- Linux Linux Kernel: from 3.1, before 3.2.44 (fixed in 3.2.44); from 3.3, before 3.4.49 (fixed in 3.4.49); from 3.5, before 3.8.8 (fixed in 3.8.8)
- Red Hat Enterprise Linux: version 6.0 only
- Red Hat Enterprise Mrg: version 2.0 only
- Suse Linux Enterprise Desktop: version 11 only
- Suse Linux Enterprise High Availability Extension: version 11 only
- Suse Linux Enterprise Server: version 11 only
Published 2013-04-29. Last modified 2026-06-16.