CVE-2013-4343: Canonical Ubuntu Linux

Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.

Use-after-free vulnerability in drivers/net/tun.c in the Linux kernel through 3.11.1 allows local users to gain privileges by leveraging the CAP_NET_ADMIN capability and providing an invalid tuntap interface name in a TUNSETIFF ioctl call.

Affected products

  • Canonical Ubuntu Linux: version 13.04 only; version 13.10 only
  • Linux Linux Kernel: from 3.8, before 3.10.16 (fixed in 3.10.16); from 3.11, before 3.11.5 (fixed in 3.11.5)

Published 2013-09-25. Last modified 2026-06-16.