PT-2014-5122 · Linux+5 · Linux Kernel+5

Ben Hawkes

·

Published

2014-09-09

·

Updated

2023-12-29

·

CVE-2014-3182

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.16.2
Description The issue is related to an array index error in the logi dj raw event function in drivers/hid/hid-logitech-dj.c. This error allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORT TYPE NOTIF DEVICE UNPAIRED value.
Recommendations For Linux kernel versions prior to 3.16.2, update to version 3.16.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the logi dj raw event function in drivers/hid/hid-logitech-dj.c to minimize the risk of exploitation.

Exploit

Fix

DoS

Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2106
ALT-PU-2015-1794
CESA-2014_1971
CVE-2014-3182
OPENSUSE-SU-2014_1669-1
OPENSUSE-SU-2014_1677-1
RHSA-2014:1318
RHSA-2014:1971
RHSA-2014_1971
USN-2376-1
USN-2377-1
USN-2394-1
USN-2395-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu