PT-2014-3533 · Linux+4 · Linux Kernel+4

Published

2014-06-19

·

Updated

2023-02-13

·

CVE-2014-0203

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 2.6.33
Description The issue is related to the do follow link function in fs/namei.c, which does not properly handle the last pathname component during use of certain filesystems. This allows local users to cause a denial of service, resulting in incorrect free operations and a system crash, via an open system call.
Recommendations For Linux kernel versions prior to 2.6.33, update to version 2.6.33 or later to resolve the issue.

Exploit

Fix

DoS

Use After Free

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1802
CESA-2014_0771
CVE-2014-0203
DLA-0015-1
RHSA-2014:0771
RHSA-2014_0771
SUSE-SU-2015:0652-1
USN-2332-1
USN-2333-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse