CVE-2014-0181Kernel vulnerability

CWE-26413 documents9 sources
Severity
2.1LOWNVD
EPSS
0.0%
top 92.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 27
Latest updateMay 13

Description

The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.

CVSS vector

AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9

Affected Packages8 packages

Patches

🔴Vulnerability Details

6
GHSA
GHSA-759j-fmr2-pgj3: The Netlink implementation in the Linux kernel through 32022-05-13
OSV
linux vulnerabilities2014-09-02
Kernel
netlink: Only check file credentials for implicit destinations2014-05-30
CVEList
CVE-2014-0181: The Netlink implementation in the Linux kernel through 32014-04-27
OSV
CVE-2014-0181: The Netlink implementation in the Linux kernel through 32014-04-27

📋Vendor Advisories

4
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2014-09-02
Ubuntu
Linux kernel vulnerabilities2014-09-02
Red Hat
kernel: net: insufficient permision checks of netlink messages2014-04-23
Debian
CVE-2014-0181: linux - The Netlink implementation in the Linux kernel through 3.14.1 does not provide a...2014

💬Community

2
Bugzilla
CVE-2014-0181 kernel: net: insufficient permision checks of netlink messages2014-05-05
Bugzilla
CVE-2014-0181 kernel: net: insufficient permision checks of netlink messages [fedora-all]2014-05-05
CVE-2014-0181 — Linux Kernel vulnerability | cvebase