PT-2014-1029 · Linux+4 · Linux Kernel+4

Jiri Slaby

·

Publicado

2013-04-23

·

Atualizado

2025-09-29

·

CVE-2014-0196

CVSS v2.0

6.9

Média

VetorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux Kernel versions through 3.14.3
Description The issue is related to errors in the implementation of access to shared resources in the Linux operating system. It allows for the exploitation of a race condition in the n tty write function, which can lead to a denial of service or privilege escalation by triggering a race condition involving read and write operations with long strings. This can result in memory corruption and system crash.
Recommendations For Linux Kernel versions through 3.14.3, consider applying a patch to fix the n tty write function in drivers/tty/n tty.c to properly manage tty driver access in the "LECHO & !OPOST" case. As a temporary workaround, consider restricting access to the tty driver to minimize the risk of exploitation.

Exploit

Correção

DoS

Race Condition

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

ALSA-2025_16880
ALT-PU-2014-1598
ALT-PU-2014-1599
ALT-PU-2014-1634
ALT-PU-2014-1776
ALT-PU-2014-1802
ALT-PU-2014-2064
BDU:2014-00109
BDU:2014-00333
CVE-2014-0196
DSA-2926-1
DSA-2928-1
ELSA-2014-0678
ELSA-2014-3034
ELSA-2014-3053
ELSA-2014-3054
MGASA-2014-0225
MGASA-2014-0226
MGASA-2014-0227
MGASA-2014-0228
MGASA-2014-0229
MGASA-2014-0234
MGASA-2014-0235
MGASA-2014-0236
MGASA-2014-0237
MGASA-2014-0238
OPENSUSE-SU-2014_0677-1
OPENSUSE-SU-2014_0678-1
OPENSUSE-SU-2024:10128-1
RHSA-2013:0744
RHSA-2013_0744
RHSA-2014:0512
RHSA-2014:0520
RHSA-2014:0557
RHSA-2014:0678
RHSA-2014_0678
SUSE-RU-2015:0621-1
SUSE-SU-2014_0667-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2196-1
USN-2197-1
USN-2198-1
USN-2199-1
USN-2200-1
USN-2201-1
USN-2202-1
USN-2203-1
USN-2204-1
USN-2227-1
USN-2260-1

Produtos afetados

Alt Linux
Linux Kernel
Red Hat
Suse
Ubuntu