CVE-2013-4588: Canonical Ubuntu Linux

High severity, CVSS 7.0. EPSS: 0.4% chance of exploitation in the next 30 days.

Multiple stack-based buffer overflows in net/netfilter/ipvs/ip_vs_ctl.c in the Linux kernel before 2.6.33, when CONFIG_IP_VS is used, allow local users to gain privileges by leveraging the CAP_NET_ADMIN capability for (1) a getsockopt system call, related to the do_ip_vs_get_ctl function, or (2) a setsockopt system call, related to the do_ip_vs_set_ctl function.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only
  • Linux Linux Kernel: before 2.6.33 (fixed in 2.6.33)

Published 2013-11-20. Last modified 2026-06-16.