PT-2014-1827 · Linux+4 · Linux Kernel+4

Published

2014-08-01

·

Updated

2020-08-14

·

CVE-2014-5045

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Red Hat Enterprise Linux kernel versions prior to 3.15.8 Red Hat Enterprise Linux kernel-bootwrapper-2.6.32 Red Hat Enterprise Linux kernel-debuginfo-common-s390x-2.6.32
Description The issue affects the Linux kernel and may lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. A function in the Linux kernel does not properly maintain a reference count during attempts to use the umount system call in conjunction with a symlink, allowing local users to cause a denial of service or possibly have other impacts.
Recommendations For Red Hat Enterprise Linux kernel versions prior to 3.15.8, update to version 3.15.8 or later to resolve the issue. For Red Hat Enterprise Linux kernel-bootwrapper-2.6.32 and kernel-debuginfo-common-s390x-2.6.32, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Link Following

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1970
ALT-PU-2015-1794
BDU:2015-06243
BDU:2015-06250
CESA-2014_1392
CESA-2014_1971
CVE-2014-5045
MGASA-2014-0316
MGASA-2014-0336
MGASA-2014-0337
MGASA-2015-0077
RHSA-2014:1392
RHSA-2014:1971
RHSA-2014_1392
RHSA-2014_1971
RHSA-2015:0062
USN-2336-1
USN-2337-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Ubuntu