PT-2013-6340 · Linux+5 · Linux Kernel+5

Published

1970-01-01

·

Updated

2023-02-13

·

CVE-2014-0077

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.13.10
Description The issue allows guest OS users to cause a denial of service or possibly gain privileges on the host OS via crafted packets. This is related to the handle rx and get rx bufs functions in the Linux kernel. The vulnerability can be exploited remotely and may lead to a violation of confidentiality, integrity, and availability of protected information.
Recommendations For Linux kernel versions prior to 3.13.10, update to version 3.13.10 or later to resolve the issue. As a temporary workaround, consider restricting access to the handle rx and get rx bufs functions until a patch is available.

Exploit

Fix

DoS

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1489
ALT-PU-2014-1547
ALT-PU-2014-1606
ALT-PU-2014-2064
BDU:2015-04307
BDU:2015-04308
BDU:2015-04309
BDU:2015-04310
CESA-2014_0475
CVE-2014-0077
MGASA-2014-0206
MGASA-2014-0207
MGASA-2014-0208
MGASA-2014-0228
MGASA-2014-0229
MGASA-2014-0234
MGASA-2014-0235
MGASA-2014-0236
MGASA-2014-0237
MGASA-2014-0238
OPENSUSE-SU-2014_0840-1
OPENSUSE-SU-2014_0856-1
RHSA-2014:0475
RHSA-2014:0593
RHSA-2014:0629
RHSA-2014:0634
RHSA-2014_0475
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2221-1
USN-2223-1
USN-2224-1
USN-2225-1
USN-2226-1
USN-2227-1
USN-2228-1
USN-2260-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu