CVE-2013-4300: Linux Kernel
High severity, CVSS 7.2. EPSS: 0.4% chance of exploitation in the next 30 days.
The scm_check_creds function in net/core/scm.c in the Linux kernel before 3.11 performs a capability check in an incorrect namespace, which allows local users to gain privileges via PID spoofing.
Affected products
- Linux Linux Kernel: from 3.8.6, before 3.9 (fixed in 3.9); version 3.9 only
Published 2013-09-25. Last modified 2026-06-16.