PT-2014-4895 · Linux · Linux Kernel
CVE-2014-2739
·
Publicado
2014-04-14
·
Atualizado
2023-02-13
CVSS v2.0
4.6
Média
| Vetor | AV:A/AC:H/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 3.14.x through 3.14.1
Description
The issue is related to the
cma req handler function in the Linux kernel, which attempts to resolve an RDMA over Converged Ethernet (RoCE) address. This can be exploited by remote attackers using crafted network traffic, leading to a denial of service due to an incorrect pointer dereference and system crash.Recommendations
For Linux kernel versions 3.14.x through 3.14.1, consider disabling the
cma req handler function as a temporary workaround until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation.Exploit
Correção
RCE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Linux Kernel