PT-2014-9108 · Opensuse+4 · Crash+60

Prasad Pandit

·

Published

1970-01-01

·

Updated

2018-12-18

·

CVE-2014-4014

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions openSUSE kernel-default (affected versions not specified) openSUSE kernel-source (affected versions not specified) openSUSE kernel-debug (affected versions not specified) openSUSE kernel-desktop (affected versions not specified) openSUSE kernel-vanilla (affected versions not specified) openSUSE kernel-pae (affected versions not specified) openSUSE kernel-ec2 (affected versions not specified) openSUSE kernel-trace (affected versions not specified) openSUSE kernel-xen (affected versions not specified) openSUSE kernel-default-devel (affected versions not specified) openSUSE kernel-desktop-devel (affected versions not specified) openSUSE kernel-pae-devel (affected versions not specified) openSUSE kernel-vanilla-devel (affected versions not specified) openSUSE kernel-ec2-devel (affected versions not specified) openSUSE kernel-trace-devel (affected versions not specified) openSUSE kernel-xen-devel (affected versions not specified) openSUSE libipset3 (affected versions not specified) openSUSE ipset (affected versions not specified) openSUSE ipset-kmp-default (affected versions not specified) openSUSE ipset-kmp-pae (affected versions not specified) openSUSE ipset-kmp-xen (affected versions not specified) openSUSE ndiswrapper (affected versions not specified) openSUSE ndiswrapper-kmp-default (affected versions not specified) openSUSE ndiswrapper-kmp-pae (affected versions not specified) openSUSE ndiswrapper-kmp-desktop (affected versions not specified) openSUSE pcfclock (affected versions not specified) openSUSE pcfclock-kmp-default (affected versions not specified) openSUSE pcfclock-kmp-pae (affected versions not specified) openSUSE pcfclock-kmp-desktop (affected versions not specified) openSUSE vhba-kmp-default (affected versions not specified) openSUSE vhba-kmp-pae (affected versions not specified) openSUSE vhba-kmp-xen (affected versions not specified) openSUSE xtables-addons (affected versions not specified) openSUSE xtables-addons-kmp-default (affected versions not specified) openSUSE xtables-addons-kmp-pae (affected versions not specified) openSUSE xtables-addons-kmp-xen (affected versions not specified) openSUSE xtables-addons-kmp-desktop (affected versions not specified) openSUSE iscsitarget (affected versions not specified) openSUSE iscsitarget-kmp-default (affected versions not specified) openSUSE iscsitarget-kmp-pae (affected versions not specified) openSUSE iscsitarget-kmp-xen (affected versions not specified) openSUSE iscsitarget-kmp-desktop (affected versions not specified) openSUSE cloop (affected versions not specified) openSUSE cloop-kmp-default (affected versions not specified) openSUSE cloop-kmp-pae (affected versions not specified) openSUSE cloop-kmp-xen (affected versions not specified) openSUSE cloop-kmp-desktop (affected versions not specified) openSUSE hdjmod (affected versions not specified) openSUSE hdjmod-kmp-default (affected versions not specified) openSUSE hdjmod-kmp-pae (affected versions not specified) openSUSE hdjmod-kmp-xen (affected versions not specified) openSUSE hdjmod-kmp-desktop (affected versions not specified) openSUSE crash (affected versions not specified) openSUSE crash-kmp-default (affected versions not specified) openSUSE crash-kmp-pae (affected versions not specified) openSUSE crash-kmp-xen (affected versions not specified) openSUSE crash-kmp-desktop (affected versions not specified)
Description The Linux kernel has multiple vulnerabilities that can be exploited to compromise the confidentiality, integrity, and availability of protected information. These vulnerabilities can be exploited remotely. Local users can bypass intended chmod restrictions by creating a user namespace and setting the setgid bit on a file with group ownership of root.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1777
ALT-PU-2014-1778
ALT-PU-2014-1779
ALT-PU-2014-1795
ALT-PU-2014-2064
BDU:2015-05685
BDU:2015-05686
BDU:2015-05687
BDU:2015-05688
BDU:2015-05689
BDU:2015-05690
BDU:2015-05691
BDU:2015-05692
BDU:2015-05693
BDU:2015-05694
BDU:2015-05695
BDU:2015-05696
BDU:2015-05697
BDU:2015-05698
BDU:2015-05699
BDU:2015-05700
BDU:2015-05701
BDU:2015-05702
BDU:2015-05703
BDU:2015-05704
BDU:2015-05705
BDU:2015-05706
BDU:2015-05707
BDU:2015-05708
BDU:2015-05709
BDU:2015-05710
BDU:2015-05711
BDU:2015-05712
BDU:2015-05713
BDU:2015-05714
BDU:2015-05715
BDU:2015-05716
BDU:2015-05717
BDU:2015-05718
BDU:2015-05719
BDU:2015-05720
BDU:2015-05721
BDU:2015-05722
BDU:2015-05723
BDU:2015-05724
BDU:2015-05725
BDU:2015-05726
BDU:2015-05727
BDU:2015-05728
BDU:2015-05729
BDU:2015-05730
BDU:2015-05731
BDU:2015-05732
BDU:2015-05733
BDU:2015-05734
BDU:2015-05735
BDU:2015-05736
BDU:2015-05737
BDU:2015-05738
BDU:2015-05739
BDU:2015-05740
BDU:2015-05741
BDU:2015-05742
BDU:2015-05743
BDU:2015-05744
BDU:2015-05745
BDU:2015-05746
BDU:2015-05747
BDU:2015-05748
BDU:2015-05749
BDU:2015-05750
BDU:2015-05751
BDU:2015-05752
BDU:2015-05753
BDU:2015-05754
BDU:2015-05755
BDU:2015-05756
BDU:2015-05757
BDU:2015-05758
BDU:2015-05759
BDU:2015-05760
BDU:2015-05761
BDU:2015-05762
BDU:2015-05763
BDU:2015-05764
BDU:2015-05765
BDU:2015-05766
BDU:2015-05767
BDU:2015-05768
BDU:2015-05769
BDU:2015-05770
BDU:2015-05771
BDU:2015-05772
BDU:2015-05773
BDU:2015-05774
BDU:2015-05775
BDU:2015-05776
BDU:2015-05777
BDU:2015-05778
BDU:2015-05779
BDU:2015-05780
BDU:2015-05781
BDU:2015-05782
BDU:2015-05783
BDU:2015-05784
BDU:2015-05785
BDU:2015-05786
BDU:2015-05787
BDU:2015-05788
BDU:2015-05789
BDU:2015-05790
BDU:2015-05791
BDU:2015-05792
BDU:2015-05793
BDU:2015-05794
BDU:2015-05795
BDU:2015-05796
BDU:2015-05797
BDU:2015-05798
BDU:2015-05799
BDU:2015-05800
BDU:2015-05801
BDU:2015-05802
BDU:2015-05803
BDU:2015-05804
BDU:2015-05805
BDU:2015-05806
BDU:2015-05807
BDU:2015-05808
BDU:2015-05809
BDU:2015-05810
BDU:2015-05811
BDU:2015-05812
BDU:2015-05813
BDU:2015-05814
BDU:2015-05815
BDU:2015-05816
BDU:2015-05817
BDU:2015-05818
BDU:2015-05819
BDU:2015-05820
BDU:2015-05821
BDU:2015-05822
BDU:2015-05823
BDU:2015-05824
BDU:2015-05825
BDU:2015-05826
BDU:2015-05827
BDU:2015-05828
BDU:2015-05829
BDU:2015-05830
BDU:2015-05831
BDU:2015-05832
BDU:2015-05833
BDU:2015-05834
BDU:2015-05835
BDU:2015-05836
BDU:2015-05837
BDU:2015-05838
BDU:2015-05839
BDU:2015-05840
BDU:2015-05841
BDU:2015-05842
BDU:2015-05843
CVE-2014-4014
MGASA-2014-0273
MGASA-2014-0316
MGASA-2014-0330
MGASA-2014-0331
MGASA-2014-0332
MGASA-2014-0336
MGASA-2014-0337
MGASA-2015-0077
OPENSUSE-SU-2014_0957-1
OPENSUSE-SU-2014_0985-1
USN-2285-1
USN-2286-1
USN-2287-1
USN-2289-1
USN-2336-1
USN-2337-1

Affected Products

Alt Linux
Linux Kernel
Suse
Ubuntu
Cloop
Cloop-Kmp-Default
Cloop-Kmp-Desktop
Cloop-Kmp-Pae
Cloop-Kmp-Xen
Crash
Crash-Kmp-Default
Crash-Kmp-Desktop
Crash-Kmp-Pae
Crash-Kmp-Xen
Hdjmod
Hdjmod-Kmp-Default
Hdjmod-Kmp-Desktop
Hdjmod-Kmp-Pae
Hdjmod-Kmp-Xen
Ipset
Ipset-Kmp-Default
Ipset-Kmp-Pae
Ipset-Kmp-Xen
Iscsitarget
Iscsitarget-Kmp-Default
Iscsitarget-Kmp-Desktop
Iscsitarget-Kmp-Pae
Iscsitarget-Kmp-Xen
Kernel-Debug
Kernel-Default
Kernel-Default-Devel
Kernel-Desktop
Kernel-Desktop-Devel
Kernel-Ec2
Kernel-Ec2-Devel
Kernel-Pae
Kernel-Pae-Devel
Kernel-Source
Kernel-Trace
Kernel-Trace-Devel
Kernel-Vanilla
Kernel-Vanilla-Devel
Kernel-Xen
Kernel-Xen-Devel
Libipset3
Ndiswrapper
Ndiswrapper-Kmp-Default
Ndiswrapper-Kmp-Desktop
Ndiswrapper-Kmp-Pae
Pcfclock
Pcfclock-Kmp-Default
Pcfclock-Kmp-Desktop
Pcfclock-Kmp-Pae
Vhba-Kmp-Default
Vhba-Kmp-Pae
Vhba-Kmp-Xen
Xtables-Addons
Xtables-Addons-Kmp-Default
Xtables-Addons-Kmp-Desktop
Xtables-Addons-Kmp-Pae
Xtables-Addons-Kmp-Xen