cbcvebase.
CVE-2014-0100
published 2014-03-11

CVE-2014-0100: Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of…

PriorityP340critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.99%
85.9th percentile
Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of service (use-after-free error) or possibly have unspecified other impact via a large series of fragmented ICMP Echo Request packets to a system with a heavy CPU load.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.13.6-1 (bookworm)linux 3.13.6-1 (bookworm)
linuxlinux_kernel>= 0 < 3.13.6-13.13.6-1
linuxlinux_kernel>= 0 < 3.13.6-13.13.6-1
linuxlinux_kernel>= 0 < 3.13.6-13.13.6-1
linuxlinux_kernel>= 0 < 3.13.6-13.13.6-1
linuxlinux_kernel>= 3.11 < 3.12.183.12.18
linuxlinux_kernel>= 3.13 < 3.13.103.13.10
linuxlinux_kernel>= 3.9 < 3.10.373.10.37

CVSS provenance

nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.