CVE-2014-0069
The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes, which allows local users to obtain sensitive information from…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.41%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes, which allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory corruption and system crash), or possibly gain privileges via a writev system call with a crafted pointer.
- CVSS 2.0
- 7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- linux/linux kernel · suse/linux enterprise desktop · suse/linux enterprise server · redhat/enterprise linux desktop · redhat/enterprise linux eus · redhat/enterprise linux server · redhat/enterprise linux server aus · redhat/enterprise linux server tus · redhat/enterprise linux workstation
- Source
- secalert@redhat.com
References
- http://article.gmane.org/gmane.linux.kernel.cifs/9401Broken Link
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5d81de8e8667da7135d3a32a964087c0faf5483fBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00026.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0328.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/02/17/4Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/65588Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1064253Issue Tracking, Third Party Advisory
- https://github.com/torvalds/linux/commit/5d81de8e8667da7135d3a32a964087c0faf5483fPatch, Third Party Advisory
- http://article.gmane.org/gmane.linux.kernel.cifs/9401Broken Link
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5d81de8e8667da7135d3a32a964087c0faf5483fBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00026.htmlMailing List, Third Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0328.htmlThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/02/17/4Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/65588Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1064253Issue Tracking, Third Party Advisory
- https://github.com/torvalds/linux/commit/5d81de8e8667da7135d3a32a964087c0faf5483fPatch, Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.