CVE-2013-4129: Linux Kernel

Medium severity, CVSS 4.7. EPSS: 0.5% chance of exploitation in the next 30 days.

The bridge multicast implementation in the Linux kernel through 3.10.3 does not check whether a certain timer is armed before modifying the timeout value of that timer, which allows local users to cause a denial of service (BUG and system crash) via vectors involving the shutdown of a KVM virtual machine, related to net/bridge/br_mdb.c and net/bridge/br_multicast.c.

Affected products

  • Linux Linux Kernel: version 3.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; version 3.0.5 only; …

Published 2013-07-29. Last modified 2026-06-16.