PT-2013-6311 · Linux+5 · Linux Kernel+5

Sasha Levin

·

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2014-3122

CVSS v2.0

4.9

Medium

VectorAV:L/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.14.3
Description The issue is related to errors in memory handling, specifically in the try to unmap cluster function in mm/rmap.c, which does not properly consider which pages must be locked. This allows local users to cause a denial of service (system crash) by triggering a memory-usage pattern that requires removal of page-table mappings. The vulnerability can be exploited to disrupt confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel versions prior to 3.14.3, update to version 3.14.3 or later to resolve the issue. As a temporary workaround, consider restricting access to sensitive memory areas to minimize the risk of exploitation.

Exploit

Fix

DoS

Resource Exhaustion

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1602
ALT-PU-2014-1604
ALT-PU-2014-1605
ALT-PU-2014-1776
ALT-PU-2014-2064
BDU:2014-00060
BDU:2014-00336
BDU:2015-04307
BDU:2015-04308
BDU:2015-04309
BDU:2015-04310
CESA-2014_1392
CVE-2014-3122
DLA-0015-1
DSA-2926-1
OPENSUSE-SU-2014_0840-1
OPENSUSE-SU-2014_0856-1
RHSA-2014:0557
RHSA-2014:1392
RHSA-2014_1392
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2223-1
USN-2224-1
USN-2233-1
USN-2234-1
USN-2235-1
USN-2236-1
USN-2239-1
USN-2240-1
USN-2241-1
USN-2260-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu