PT-2017-6406 · Linux+1 · Linux Kernel+1

Alexey Preobrazhensky

+1

·

Published

2014-06-26

·

Updated

2023-01-18

·

CVE-2014-9914

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.15.2
Description A race condition in the ip4 datagram release cb function allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.
Recommendations For Linux kernel versions prior to 3.15.2, update to version 3.15.2 or later to resolve the issue. As a temporary workaround, consider restricting access to IPv4 UDP sockets to minimize the risk of exploitation.

Fix

DoS

Use After Free

Race Condition

Weakness Enumeration

Related Identifiers

ALT-PU-2014-1823
ALT-PU-2014-1847
CVE-2014-9914

Affected Products

Alt Linux
Linux Kernel