PT-2014-4895 · Linux · Linux Kernel
Published
2014-04-14
·
Updated
2023-02-13
·
CVE-2014-2739
CVSS v2.0
4.6
Medium
| Vector | AV:A/AC:H/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions 3.14.x through 3.14.1
Description
The issue is related to the
cma req handler function in the Linux kernel, which attempts to resolve an RDMA over Converged Ethernet (RoCE) address. This can be exploited by remote attackers using crafted network traffic, leading to a denial of service due to an incorrect pointer dereference and system crash.Recommendations
For Linux kernel versions 3.14.x through 3.14.1, consider disabling the
cma req handler function as a temporary workaround until a patch is available. Restrict access to the vulnerable module to minimize the risk of exploitation.Exploit
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Linux Kernel