PT-2014-7216 · Linux+2 · Linux Kernel+2

Published

2014-09-19

·

Updated

2023-01-19

·

CVE-2014-6417

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.16.3
Description The issue is related to the net/ceph/auth x.c file in Ceph, as used in the Linux kernel. It does not properly consider the possibility of kmalloc failure, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a long unencrypted auth ticket.
Recommendations For Linux kernel versions prior to 3.16.3, update to version 3.16.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the auth x module to minimize the risk of exploitation.

Exploit

Fix

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2158
ALT-PU-2014-2159
CVE-2014-6417
USN-2376-1
USN-2377-1
USN-2378-1
USN-2379-1

Affected Products

Alt Linux
Linux Kernel
Ubuntu