CVE-2014-0131
published 2014-03-24CVE-2014-0131: Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive…
PriorityP411low2.9CVSS 2.0
AVAACMAuNCPINAN
EPSS
0.68%
48.5th percentile
Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.13.6-1 (bookworm) | linux 3.13.6-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.13.6-1 | 3.13.6-1 |
| linux | linux_kernel | >= 0 < 3.13.6-1 | 3.13.6-1 |
| linux | linux_kernel | >= 0 < 3.13.6-1 | 3.13.6-1 |
| linux | linux_kernel | >= 0 < 3.13.6-1 | 3.13.6-1 |
| linux | linux_kernel | 3.0 – 3.13.6 | — |
| opensuse | evergreen | — | — |
| suse | linux_enterprise_server | — | — |
CVSS provenance
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:P/I:N/A:N
osv2.9LOW
vendor_debian2.9LOW
vendor_redhat2.9LOW
vendor_ubuntu2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2014-07-17·CVSS 2.9
CVE-2014-0131 [LOW] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Michael S. Tsirkin discovered an information leak in the Linux kernel's
segmentation of skbs when using the zerocopy feature of vhost-net. A local
attacker could exploit this flaw to gain potentially sensitive information
from kernel memory. (CVE-2014-0131)
Salva Peiró discovered an information leak in the Linux kernel's media-
device driver. A local attacker could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2014-1739)
An flaw
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2014-07-17·CVSS 2.9
CVE-2014-0131 [LOW] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Michael S. Tsirkin discovered an information leak in the Linux kernel's
segmentation of skbs when using the zerocopy feature of vhost-net. A local
attacker could exploit this flaw to gain potentially sensitive information
from kernel memory. (CVE-2014-0131)
Salva Peiró discovered an information leak in the Linux kernel's media-
device driver. A local attacker could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2014-1739)
A bounds
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-07-17·CVSS 2.9
CVE-2014-0131 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Michael S. Tsirkin discovered an information leak in the Linux kernel's
segmentation of skbs when using the zerocopy feature of vhost-net. A local
attacker could exploit this flaw to gain potentially sensitive information
from kernel memory. (CVE-2014-0131)
An flaw was discovered in the Linux kernel's audit subsystem when auditing
certain syscalls. A local attacker could exploit this flaw to obtain
potentially sensitive single-bit values from kernel memory or cause a
denia
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-07-17·CVSS 2.9
CVE-2014-0131 [LOW] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Michael S. Tsirkin discovered an information leak in the Linux kernel's
segmentation of skbs when using the zerocopy feature of vhost-net. A local
attacker could exploit this flaw to gain potentially sensitive information
from kernel memory. (CVE-2014-0131)
An flaw was discovered in the Linux kernel's audit subsystem when auditing
certain syscalls. A local attacker could exploit this flaw to obtain
potentially sensitive single-bit values from kernel memory or c
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-07-16·CVSS 2.9
CVE-2014-0131 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Michael S. Tsirkin discovered an information leak in the Linux kernel's
segmentation of skbs when using the zerocopy feature of vhost-net. A local
attacker could exploit this flaw to gain potentially sensitive information
from kernel memory. (CVE-2014-0131)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, whic
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-07-16·CVSS 2.9
CVE-2014-0131 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Andy Lutomirski discovered a flaw with the Linux kernel's ptrace syscall on
x86_64 processors. An attacker could exploit this flaw to cause a denial of
service (System Crash) or potential gain administrative privileges.
(CVE-2014-4699)
Michael S. Tsirkin discovered an information leak in the Linux kernel's
segmentation of skbs when using the zerocopy feature of vhost-net. A local
attacker could exploit this flaw to gain potentially sensitive information
from kernel
Red Hat
kernel: net: use-after-free during segmentation with zerocopy
vendor_redhat·2014-03-10·CVSS 2.9
CVE-2014-0131 [LOW] CWE-416 kernel: net: use-after-free during segmentation with zerocopy
kernel: net: use-after-free during segmentation with zerocopy
Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.
Statement: This issue does not affect Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
This issue affects the Linux kernel package as shipped with Red Hat Enterprise Linux 6.
Red Hat Product Security has rated this issue as having Low security impact. The risks and engineering effort associated with fixing this bug are greater
than its security impact. This issue is not currently planned to be addressed
in future kernel updates for Red Hat Enterprise Linux 6. For additional
informat
Debian
CVE-2014-0131: linux - Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in...
vendor_debian·2014·CVSS 2.9
CVE-2014-0131 [LOW] CVE-2014-0131: linux - Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in...
Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.
Scope: local
bookworm: resolved (fixed in 3.13.6-1)
bullseye: resolved (fixed in 3.13.6-1)
forky: resolved (fixed in 3.13.6-1)
sid: resolved (fixed in 3.13.6-1)
trixie: resolved (fixed in 3.13.6-1)
VulDB
Linux Kernel up to 3.13.6 vhost-net Segmentation net/core/skbuff.c skb_segment resource management (Nessus ID 73241 / ID 167699)
vuldb·2026-05-08·CVSS 2.9
CVE-2014-0131 [LOW] Linux Kernel up to 3.13.6 vhost-net Segmentation net/core/skbuff.c skb_segment resource management (Nessus ID 73241 / ID 167699)
A vulnerability was found in Linux Kernel up to 3.13.6. It has been declared as problematic. Impacted is the function skb_segment of the file net/core/skbuff.c of the component vhost-net Segmentation. The manipulation results in improper resource management.
This vulnerability is reported as CVE-2014-0131. The attacker must have access to the local network to execute the attack. No exploit exists.
It is advisable to implement a patch to correct this issue.
GHSA
GHSA-69px-r2hq-hmw3: Use-after-free vulnerability in the skb_segment function in net/core/skbuff
ghsa_unreviewed·2022-05-14
CVE-2014-0131 [LOW] CWE-416 GHSA-69px-r2hq-hmw3: Use-after-free vulnerability in the skb_segment function in net/core/skbuff
Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.
OSV
CVE-2014-0131: Use-after-free vulnerability in the skb_segment function in net/core/skbuff
osv·2014-03-24·CVSS 2.9
CVE-2014-0131 [LOW] CVE-2014-0131: Use-after-free vulnerability in the skb_segment function in net/core/skbuff
Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0131 kernel: net: use-after-free during segmentation with zerocopy [fedora-all]
bugzilla·2014-03-20·CVSS 2.9
CVE-2014-0131 [LOW] CVE-2014-0131 kernel: net: use-after-free during segmentation with zerocopy [fedora-all]
CVE-2014-0131 kernel: net: use-after-free during segmentation with zerocopy [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: thi
Bugzilla
CVE-2014-0131 kernel: net: use-after-free during segmentation with zerocopy
bugzilla·2014-03-10·CVSS 2.9
CVE-2014-0131 [LOW] CVE-2014-0131 kernel: net: use-after-free during segmentation with zerocopy
CVE-2014-0131 kernel: net: use-after-free during segmentation with zerocopy
An information leak flaw was found in the way way segmentation was performed on skbs originated from vhost-net when zerocopy feature was enabled. Once the source skb is consumed, ubuf destructor is called and potentially releases the corresponding userspace buffers, which can then for example be repurposed, while the destination skb could still be pointing to the them.
Acknowledgements:
This issue was discovered by Michael S. Tsirkin of Red Hat.
Discussion:
Upstream patch submission:
http://marc.info/?l=linux-netdev&m=139446896921968&w=2
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1079006]
---
Statement:
This issue does not affect Red Hat Enterprise Linux 5 and Red Hat Ente
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1fd819ecb90cc9b822cd84d3056ddba315d3340fhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://www.openwall.com/lists/oss-security/2014/03/10/4http://www.spinics.net/lists/netdev/msg274250.htmlhttp://www.spinics.net/lists/netdev/msg274316.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1074589https://github.com/torvalds/linux/commit/1fd819ecb90cc9b822cd84d3056ddba315d3340fhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=1fd819ecb90cc9b822cd84d3056ddba315d3340fhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://www.openwall.com/lists/oss-security/2014/03/10/4http://www.spinics.net/lists/netdev/msg274250.htmlhttp://www.spinics.net/lists/netdev/msg274316.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1074589https://github.com/torvalds/linux/commit/1fd819ecb90cc9b822cd84d3056ddba315d3340f
2014-03-24
Published