{
  "threat_severity" : "Moderate",
  "public_date" : "2012-09-13T00:00:00Z",
  "bugzilla" : {
    "description" : "Kernel: xfrm_user: return error pointer instead of NULL",
    "id" : "919384",
    "url" : "https://bugzilla.redhat.com/show_bug.cgi?id=919384"
  },
  "cvss" : {
    "cvss_base_score" : "3.8",
    "cvss_scoring_vector" : "AV:L/AC:H/Au:S/C:N/I:N/A:C",
    "status" : "verified"
  },
  "details" : [ "The xfrm_state_netlink function in net/xfrm/xfrm_user.c in the Linux kernel before 3.5.7 does not properly handle error conditions in dump_one_state function calls, which allows local users to gain privileges or cause a denial of service (NULL pointer dereference and system crash) by leveraging the CAP_NET_ADMIN capability." ],
  "statement" : "This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise MRG 2.\nThis issue did affect the version of the Linux kernel as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6.",
  "affected_release" : [ {
    "product_name" : "Red Hat Enterprise Linux 5",
    "release_date" : "2013-04-16T00:00:00Z",
    "advisory" : "RHSA-2013:0747",
    "cpe" : "cpe:/o:redhat:enterprise_linux:5",
    "package" : "kernel-0:2.6.18-348.4.1.el5"
  }, {
    "product_name" : "Red Hat Enterprise Linux 6",
    "release_date" : "2013-04-23T00:00:00Z",
    "advisory" : "RHSA-2013:0744",
    "cpe" : "cpe:/o:redhat:enterprise_linux:6",
    "package" : "kernel-0:2.6.32-358.6.1.el6"
  } ],
  "package_state" : [ {
    "product_name" : "Red Hat Enterprise MRG 2",
    "fix_state" : "Not affected",
    "package_name" : "realtime-kernel",
    "cpe" : "cpe:/a:redhat:enterprise_mrg:2"
  } ],
  "references" : [ "https://www.cve.org/CVERecord?id=CVE-2013-1826\nhttps://nvd.nist.gov/vuln/detail/CVE-2013-1826" ],
  "name" : "CVE-2013-1826",
  "csaw" : false
}