PT-2014-7805 · Linux+4 · Linux Kernel+4

Raphael Geissert

·

Published

2014-09-19

·

Updated

2023-01-18

·

CVE-2014-7145

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.16.3
Description The issue allows remote CIFS servers to cause a denial of service, resulting in a NULL pointer dereference and client system crash, or possibly have unspecified other impact. This occurs when the IPC$ share is deleted during resolution of DFS referrals. The SMB2 tcon function in fs/cifs/smb2pdu.c is the vulnerable component.
Recommendations For Linux kernel versions prior to 3.16.3, update to version 3.16.3 or later to resolve the issue. As a temporary workaround, consider restricting access to the SMB2 tcon function in fs/cifs/smb2pdu.c to minimize the risk of exploitation.

Fix

DoS

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2158
ALT-PU-2014-2159
CESA-2015_0102
CVE-2014-7145
RHSA-2015:0102
RHSA-2015_0102
USN-2394-1
USN-2395-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Ubuntu