PT-2017-6406 · Linux+1 · Linux Kernel+1
Alexey Preobrazhensky
+1
·
Publicado
2014-06-26
·
Atualizado
2023-01-18
·
CVE-2014-9914
CVSS v3.1
7.8
Alta
| Vetor | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 3.15.2
Description
A race condition in the
ip4 datagram release cb function allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.Recommendations
For Linux kernel versions prior to 3.15.2, update to version 3.15.2 or later to resolve the issue. As a temporary workaround, consider restricting access to IPv4 UDP sockets to minimize the risk of exploitation.
Correção
DoS
Use After Free
Race Condition
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Linux Kernel