CVE-2013-2850
EPSS 7.3%
Description
Heap-based buffer overflow in the iscsi_add_notunderstood_response function in drivers/target/iscsi/iscsi_target_parameters.c in the iSCSI target subsystem in the Linux kernel through 3.9.4 allows remote attackers to cause a denial of service (memory corruption and OOPS) or possibly execute arbitrary code via a long key that is not properly handled during construction of an error-response packet.
How to fix CVE-2013-2850
To remediate CVE-2013-2850, upgrade the affected package to a fixed version below.
- Debian/linux—upgrade to 3.9.4-1 or later
Is CVE-2013-2850 being exploited?
Moderate — EPSS is 7.3%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 3.9.4-1