CVE-2014-0100
published 2014-03-11CVE-2014-0100: Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of…
PriorityP340critical9.3CVSS 2.0
AVNACMAuNCCICAC
EPSS
2.99%
85.9th percentile
Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of service (use-after-free error) or possibly have unspecified other impact via a large series of fragmented ICMP Echo Request packets to a system with a heavy CPU load.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.13.6-1 (bookworm) | linux 3.13.6-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.13.6-1 | 3.13.6-1 |
| linux | linux_kernel | >= 0 < 3.13.6-1 | 3.13.6-1 |
| linux | linux_kernel | >= 0 < 3.13.6-1 | 3.13.6-1 |
| linux | linux_kernel | >= 0 < 3.13.6-1 | 3.13.6-1 |
| linux | linux_kernel | >= 3.11 < 3.12.18 | 3.12.18 |
| linux | linux_kernel | >= 3.13 < 3.13.10 | 3.13.10 |
| linux | linux_kernel | >= 3.9 < 3.10.37 | 3.10.37 |
CVSS provenance
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv9.3CRITICAL
vendor_debian9.3CRITICAL
vendor_redhat9.3CRITICAL
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-05-27·CVSS 5.5
CVE-2014-0055 [MEDIUM] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in the handling of ioctl commands by the
floppy disk driver in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges if the floppy disk
module is loaded. (CVE-2014-1737)
A flaw was discovered in the vhost-net subsystem of the Linux kernel. Guest
OS users could exploit this flaw to cause a denial of service (host OS
crash). (CVE-2014-0055)
A flaw was discovered in the handling of networ
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-05-27·CVSS 5.5
CVE-2014-0055 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in the handling of ioctl commands by the
floppy disk driver in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges if the floppy disk
module is loaded. (CVE-2014-1737)
A flaw was discovered in the vhost-net subsystem of the Linux kernel. Guest
OS users could exploit this flaw to cause a denial of service (host OS
crash). (CVE-2014-0055)
A flaw was discovered in the handling of network packets wh
Red Hat
kernel: net: inet frag code race condition leading to user-after-free
vendor_redhat·2014-03-03·CVSS 9.3
CVE-2014-0100 [CRITICAL] kernel: net: inet frag code race condition leading to user-after-free
kernel: net: inet frag code race condition leading to user-after-free
Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of service (use-after-free error) or possibly have unspecified other impact via a large series of fragmented ICMP Echo Request packets to a system with a heavy CPU load.
Statement: This issue did not affect the versions of Linux kernel package as shipped with Red Hat Enterprise Linux 5 and 6 as they did not backport the commit that introduced this issue.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Debian
CVE-2014-0100: linux - Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in t...
vendor_debian·2014·CVSS 9.3
CVE-2014-0100 [CRITICAL] CVE-2014-0100: linux - Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in t...
Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of service (use-after-free error) or possibly have unspecified other impact via a large series of fragmented ICMP Echo Request packets to a system with a heavy CPU load.
Scope: local
bookworm: resolved (fixed in 3.13.6-1)
bullseye: resolved (fixed in 3.13.6-1)
forky: resolved (fixed in 3.13.6-1)
sid: resolved (fixed in 3.13.6-1)
trixie: resolved (fixed in 3.13.6-1)
GHSA
GHSA-vrjq-5hcv-6mhv: Race condition in the inet_frag_intern function in net/ipv4/inet_fragment
ghsa_unreviewed·2022-05-13
CVE-2014-0100 [HIGH] CWE-362 GHSA-vrjq-5hcv-6mhv: Race condition in the inet_frag_intern function in net/ipv4/inet_fragment
Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of service (use-after-free error) or possibly have unspecified other impact via a large series of fragmented ICMP Echo Request packets to a system with a heavy CPU load.
Kernel
KEYS: Change the name of the dead type to ".dead" to prevent user access
kernel_security·2017-04-18·CVSS 5.5
CVE-2017-6951 [MEDIUM] KEYS: Change the name of the dead type to ".dead" to prevent user access
KEYS: Change the name of the dead type to ".dead" to prevent user access
This fixes CVE-2017-6951.
Userspace should not be able to do things with the "dead" key type as it
doesn't have some of the helper functions set upon it that the kernel
needs. Attempting to use it may cause the kernel to crash.
Fix this by changing the name of the type to ".dead" so that it's rejected
up front on userspace syscalls by key_get_type_from_user().
Though this doesn't seem to affect recent kernels, it does affect older
ones, certainly those prior to:
commit c06cfb08b88dfbe13be44a69ae2fdc3a7c902d81
Author: David Howells
Date: Tue Sep 16 17:36:06 2014 +0100
KEYS: Remove key_type::match in favour of overriding default by match_preparse
which went in before 3.18-rc1.
Signed-off-by: David Howells
cc: sta
OSV
CVE-2014-0100: Race condition in the inet_frag_intern function in net/ipv4/inet_fragment
osv·2014-03-11·CVSS 9.3
CVE-2014-0100 [CRITICAL] CVE-2014-0100: Race condition in the inet_frag_intern function in net/ipv4/inet_fragment
Race condition in the inet_frag_intern function in net/ipv4/inet_fragment.c in the Linux kernel through 3.13.6 allows remote attackers to cause a denial of service (use-after-free error) or possibly have unspecified other impact via a large series of fragmented ICMP Echo Request packets to a system with a heavy CPU load.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0100 kernel: net: inet frag code race condition leading to user-after-free [fedora-all]
bugzilla·2014-03-03·CVSS 9.3
CVE-2014-0100 [CRITICAL] CVE-2014-0100 kernel: net: inet frag code race condition leading to user-after-free [fedora-all]
CVE-2014-0100 kernel: net: inet frag code race condition leading to user-after-free [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please n
Bugzilla
CVE-2014-0100 kernel: net: inet frag code race condition leading to user-after-free
bugzilla·2014-02-27·CVSS 9.3
CVE-2014-0100 [CRITICAL] CVE-2014-0100 kernel: net: inet frag code race condition leading to user-after-free
CVE-2014-0100 kernel: net: inet frag code race condition leading to user-after-free
Description of the problem:
A very subtle race condition between inet_frag_evictor,
inet_frag_intern and the IPv4/6 frag_queue and expire functions (basically
the users of inet_frag_kill/inet_frag_put) was found.
What happens is that after a fragment has been added to the hash chain but
before it's been added to the lru_list (inet_frag_lru_add), it may get
deleted (either by an expired timer if the system load is high or the
timer sufficiently low, or by the fraq_queue function for different
reasons) before it's added to the lru_list, then after it gets added
it's a matter of time for the evictor to get to a piece of memory which
has been freed leading to a number of different bugs depending on what's
le
Bugzilla
CVE-2013-6383 Kernel: AACRAID Driver compat IOCTL missing capability check
bugzilla·2013-11-22·CVSS 6.9
CVE-2013-6383 [MEDIUM] CVE-2013-6383 Kernel: AACRAID Driver compat IOCTL missing capability check
CVE-2013-6383 Kernel: AACRAID Driver compat IOCTL missing capability check
Linux kernel built with the Adaptec RAID controller support(CONFIG_SCSI_AACRAID)
along with the compat mode(CONFIG_COMPAT), is vulnerable due to a missing
capability check in a compat ioctl routine. This could lead to undue usage of
restricted operations by users.
A user/program could use this flaw to perform protected operations via compat
ioctl route.
Upstream fix:
-> https://git.kernel.org/linus/f856567b930dfcdbc3323261bf77240ccdde01f5
Reference:
-> https://secunia.com/advisories/55562/
Discussion:
Statement:
(none)
---
This issue has been addressed in following products:
MRG for RHEL-6 v.2
Via RHSA-2014:0100 https://rhn.redhat.com/errata/RHSA-2014-0100.html
---
This issue has been addressed in follo
Bugzilla
CVE-2013-2929 kernel: exec/ptrace: get_dumpable() incorrect tests
bugzilla·2013-11-07·CVSS 3.3
CVE-2013-2929 [LOW] CVE-2013-2929 kernel: exec/ptrace: get_dumpable() incorrect tests
CVE-2013-2929 kernel: exec/ptrace: get_dumpable() incorrect tests
The get_dumpable() return value is not boolean. Most users of the function actually want to be testing for non-SUID_DUMP_USER(1) rather than SUID_DUMP_DISABLE(0). The SUID_DUMP_ROOT(2) is also considered a protected state.
If the system had set the sysctl fs.suid_dumpable=2, a user was able to ptrace attach to processes that he would otherwise be unable to because of the dumpable check.
Upstream fix:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d049f74f2dbe71354d43d393ac3a188947811348
Discussion:
This issue has been addressed in following products:
MRG for RHEL-6 v.2
Via RHSA-2014:0100 https://rhn.redhat.com/errata/RHSA-2014-0100.html
---
This issue has been addressed in following produc
2014-03-11
Published