PT-2014-1827 · Linux+4 · Linux Kernel+4
Published
2014-08-01
·
Updated
2020-08-14
·
CVE-2014-5045
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Red Hat Enterprise Linux kernel versions prior to 3.15.8
Red Hat Enterprise Linux kernel-bootwrapper-2.6.32
Red Hat Enterprise Linux kernel-debuginfo-common-s390x-2.6.32
Description
The issue affects the Linux kernel and may lead to disruption of confidentiality, integrity, and availability of protected information. Exploitation can be done remotely. A function in the Linux kernel does not properly maintain a reference count during attempts to use the umount system call in conjunction with a symlink, allowing local users to cause a denial of service or possibly have other impacts.
Recommendations
For Red Hat Enterprise Linux kernel versions prior to 3.15.8, update to version 3.15.8 or later to resolve the issue.
For Red Hat Enterprise Linux kernel-bootwrapper-2.6.32 and kernel-debuginfo-common-s390x-2.6.32, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
DoS
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Linux Kernel
Red Hat
Ubuntu