PT-2017-6406 · Linux+1 · Linux Kernel+1
Alexey Preobrazhensky
+1
·
Published
2014-06-26
·
Updated
2023-01-18
·
CVE-2014-9914
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 3.15.2
Description
A race condition in the
ip4 datagram release cb function allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.Recommendations
For Linux kernel versions prior to 3.15.2, update to version 3.15.2 or later to resolve the issue. As a temporary workaround, consider restricting access to IPv4 UDP sockets to minimize the risk of exploitation.
Fix
DoS
Use After Free
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Linux Kernel