CVE-2014-0181
published 2014-04-27CVE-2014-0181: The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket…
PriorityP410low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.54%
42.1th percentile
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.14.9-1 (bookworm) | linux 3.14.9-1 (bookworm) |
| linux | linux_kernel | <= 3.14.1 | — |
| linux | linux_kernel | >= 0 < 3.14.9-1 | 3.14.9-1 |
| linux | linux_kernel | >= 0 < 3.14.9-1 | 3.14.9-1 |
| linux | linux_kernel | >= 0 < 3.14.9-1 | 3.14.9-1 |
| linux | linux_kernel | >= 0 < 3.14.9-1 | 3.14.9-1 |
| linux | linux_kernel | >= 0 < 3.13.0-35.62 | 3.13.0-35.62 |
| opensuse | evergreen | — | — |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_server | — | — |
| suse | linux_enterprise_real_time_extension | — | — |
| suse | linux_enterprise_server | — | — |
| suse | linux_enterprise_server | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel mem
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-201
Red Hat
kernel: net: insufficient permision checks of netlink messages
vendor_redhat·2014-04-23·CVSS 2.1
CVE-2014-0181 [LOW] kernel: net: insufficient permision checks of netlink messages
kernel: net: insufficient permision checks of netlink messages
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
It was found that the permission checks performed by the Linux kernel when a netlink message was received were not sufficient. A local, unprivileged user could potentially bypass these restrictions by passing a netlink socket as stdout or stderr to a more privileged process and altering the output of this process.
Debian
CVE-2014-0181: linux - The Netlink implementation in the Linux kernel through 3.14.1 does not provide a...
vendor_debian·2014·CVSS 2.1
CVE-2014-0181 [LOW] CVE-2014-0181: linux - The Netlink implementation in the Linux kernel through 3.14.1 does not provide a...
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
Scope: local
bookworm: resolved (fixed in 3.14.9-1)
bullseye: resolved (fixed in 3.14.9-1)
forky: resolved (fixed in 3.14.9-1)
sid: resolved (fixed in 3.14.9-1)
trixie: resolved (fixed in 3.14.9-1)
VulDB
Linux Kernel up to 3.13.9 Netlink Socket access control (Nessus ID 73957 / ID 167678)
vuldb·2026-05-12·CVSS 2.1
CVE-2014-0181 [LOW] Linux Kernel up to 3.13.9 Netlink Socket access control (Nessus ID 73957 / ID 167678)
A vulnerability identified as problematic has been detected in Linux Kernel up to 3.13.9. The impacted element is an unknown function of the component Netlink Socket Handler. This manipulation causes improper access controls.
This vulnerability is handled as CVE-2014-0181. It is possible to launch the attack on the local host. There is not any exploit available.
Applying a patch is the recommended action to fix this issue.
GHSA
GHSA-759j-fmr2-pgj3: The Netlink implementation in the Linux kernel through 3
ghsa_unreviewed·2022-05-13
CVE-2014-0181 [LOW] GHSA-759j-fmr2-pgj3: The Netlink implementation in the Linux kernel through 3
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
OSV
linux vulnerabilities
osv·2014-09-02·CVSS 5.5
CVE-2014-0155 [MEDIUM] linux vulnerabilities
linux vulnerabilities
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-2014-0206)
A flaw was discovered in the Linux kernel's implementation of use
Kernel
netlink: Only check file credentials for implicit destinations
kernel_security·2014-05-30·CVSS 2.1
CVE-2014-0181 [LOW] netlink: Only check file credentials for implicit destinations
netlink: Only check file credentials for implicit destinations
It was possible to get a setuid root or setcap executable to write to
it's stdout or stderr (which has been set made a netlink socket) and
inadvertently reconfigure the networking stack.
To prevent this we check that both the creator of the socket and
the currentl applications has permission to reconfigure the network
stack.
Unfortunately this breaks Zebra which always uses sendto/sendmsg
and creates it's socket without any privileges.
To keep Zebra working don't bother checking if the creator of the
socket has privilege when a destination address is specified. Instead
rely exclusively on the privileges of the sender of the socket.
Note from Andy: This is exactly Eric's code except for some comment
clarifications and forma
OSV
CVE-2014-0181: The Netlink implementation in the Linux kernel through 3
osv·2014-04-27·CVSS 2.1
CVE-2014-0181 [LOW] CVE-2014-0181: The Netlink implementation in the Linux kernel through 3
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
Kernel
Merge branch 'netlink-caps'
kernel_security·2014-04-24·CVSS 2.1
CVE-2014-0181 [LOW] Merge branch 'netlink-caps'
Merge branch 'netlink-caps'
Eric W. Biederman says:
netlink: Preventing abuse when passing file descriptors.
Andy Lutomirski when looking at the networking stack noticed that it is
possible to trick privilged processes into calling write on a netlink
socket and send netlink messages they did not intend.
In particular from time to time there are suid applications that will
write to stdout or stderr without checking exactly what kind of file
descriptors those are and can be tricked into acting as a limited form
of suid cat. In other conversations the magic string CVE-2014-0181 has
been used to talk about this issue.
This patchset cleans things up a bit, adds some clean abstractions that
when used prevent this kind of problem and then finally changes all of
the handlers of netlink messag
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-0181 kernel: net: insufficient permision checks of netlink messages
bugzilla·2014-05-05·CVSS 2.1
CVE-2014-0181 [LOW] CVE-2014-0181 kernel: net: insufficient permision checks of netlink messages
CVE-2014-0181 kernel: net: insufficient permision checks of netlink messages
It is possible to reconfigure the network on Linux by calling write(2)
on an appropriately connected network socket. An unprivileged local
user could use this flaw to reconfigure the network by passing such a
socket as stdout or stderr to a setuid program.
References:
http://seclists.org/oss-sec/2014/q2/162
Upstream commit:
https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=90f62cf30a78721641e08737bda787552428061e
(depends on some of the preceding commits; whole set on http://www.spinics.net/lists/netdev/msg280198.html)
Acknowledgements:
Red Hat would like to thank Andy Lutomirski for reporting this issue.
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug
Bugzilla
CVE-2014-0181 kernel: net: insufficient permision checks of netlink messages [fedora-all]
bugzilla·2014-05-05·CVSS 2.1
CVE-2014-0181 [LOW] CVE-2014-0181 kernel: net: insufficient permision checks of netlink messages [fedora-all]
CVE-2014-0181 kernel: net: insufficient permision checks of netlink messages [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affec
http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://marc.info/?l=linux-netdev&m=139828832919748&w=2http://rhn.redhat.com/errata/RHSA-2014-1959.htmlhttp://www.openwall.com/lists/oss-security/2014/04/23/6http://www.openwall.com/lists/oss-security/2023/04/16/3https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=90f62cf30a78721641e08737bda787552428061ehttps://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.45https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.9http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://marc.info/?l=linux-netdev&m=139828832919748&w=2http://rhn.redhat.com/errata/RHSA-2014-1959.htmlhttp://www.openwall.com/lists/oss-security/2014/04/23/6http://www.openwall.com/lists/oss-security/2023/04/16/3https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=90f62cf30a78721641e08737bda787552428061ehttps://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.45https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.9
2014-04-27
Published