cbcvebase.
CVE-2014-0196
published 2014-05-07

CVE-2014-0196: The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case…

medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2023-06-02
Exploited in the wild
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

Affected

47 ranges· showing 25
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
canonicalubuntu_linux
debiandebian_linux
debiandebian_linux
debianlinux< linux 3.14.4-1 (bookworm)linux 3.14.4-1 (bookworm)
f5big-ip_access_policy_manager11.1.0 – 11.5.1
f5big-ip_advanced_firewall_manager11.3.0 – 11.5.1
f5big-ip_analytics11.1.0 – 11.5.1
f5big-ip_application_acceleration_manager11.4.0 – 11.5.1
f5big-ip_application_security_manager11.1.0 – 11.5.1
f5big-ip_edge_gateway11.1.0 – 11.3.0
f5big-ip_global_traffic_manager11.1.0 – 11.5.1
f5big-ip_link_controller11.1.0 – 11.5.1
f5big-ip_local_traffic_manager11.1.0 – 11.5.1
f5big-ip_policy_enforcement_manager11.3.0 – 11.5.1
f5big-ip_protocol_security_module11.1.0 – 11.4.1
f5big-ip_wan_optimization_manager11.1.0 – 11.3.0
f5big-ip_webaccelerator11.1.0 – 11.3.0
f5big-iq_application_delivery_controller
f5big-iq_centralized_management
f5big-iq_cloud4.0.0 – 4.5.0
f5big-iq_cloud_and_orchestration

CVSS provenance

nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
osv5.5MEDIUM
vulncheck5.5MEDIUM
cisa5.5MEDIUM