CVE-2013-4348: Canonical Ubuntu Linux
High severity, CVSS 7.1. EPSS: 9.4% chance of exploitation in the next 30 days.
The skb_flow_dissect function in net/core/flow_dissector.c in the Linux kernel through 3.12 allows remote attackers to cause a denial of service (infinite loop) via a small value in the IHL field of a packet with IPIP encapsulation.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 13.10 only
- Linux Linux Kernel: from 3.2, before 3.2.54 (fixed in 3.2.54); from 3.3, before 3.4.70 (fixed in 3.4.70); from 3.5, before 3.10.20 (fixed in 3.10.20); from 3.11, before 3.11.9 (fixed in 3.11.9); from 3.12, before 3.12.1 (fixed in 3.12.1)
Published 2013-11-04. Last modified 2026-06-16.