CVE-2014-0203
published 2014-06-23CVE-2014-0203: The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain…
PriorityP418medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.54%
42.1th percentile
The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and system crash) via an open system call.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 2.6.33-1 (bookworm) | linux 2.6.33-1 (bookworm) |
| linux | linux_kernel | < 2.6.33 | 2.6.33 |
| linux | linux_kernel | >= 0 < 2.6.33-1 | 2.6.33-1 |
| linux | linux_kernel | >= 0 < 2.6.33-1 | 2.6.33-1 |
| linux | linux_kernel | >= 0 < 2.6.33-1 | 2.6.33-1 |
| linux | linux_kernel | >= 0 < 2.6.33-1 | 2.6.33-1 |
| oracle | linux | — | — |
| oracle | linux | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-48m7-cf7p-jqm7: The __do_follow_link function in fs/namei
ghsa_unreviewed·2022-05-13
CVE-2014-0203 [MEDIUM] CWE-416 GHSA-48m7-cf7p-jqm7: The __do_follow_link function in fs/namei
The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and system crash) via an open system call.
OSV
CVE-2014-0203: The __do_follow_link function in fs/namei
osv·2014-06-23·CVSS 5.5
CVE-2014-0203 [MEDIUM] CVE-2014-0203: The __do_follow_link function in fs/namei
The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and system crash) via an open system call.
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 5.5
CVE-2014-0203 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the handling of pathname components when used with
an autofs direct mount. A local user could exploit this flaw to cause a
denial of service (system crash) via an open system call. (CVE-2014-0203)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 5.5
CVE-2014-0203 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bug was discovered in the handling of pathname components when used with
an autofs direct mount. A local user could exploit this flaw to cause a
denial of service (system crash) via an open system call. (CVE-2014-0203)
Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit x86 platforms. A local user could exploit this flaw to cause a
denial of service (OOPS and system crash). (CVE-2014-4508)
An information leak was discovered in the control implemenation of the
Advanced Linux Sound Architecture (ALSA) subsystem in the Linux kernel. A
local user could exploit this flaw to obtain sensitive information from
kernel memory. (CVE-2014-4652)
A use-after-free flaw was di
Red Hat
kernel: fs: slab corruption due to the invalid last component type during do_filp_open()
vendor_redhat·2014-06-19·CVSS 5.5
CVE-2014-0203 [MEDIUM] kernel: fs: slab corruption due to the invalid last component type during do_filp_open()
kernel: fs: slab corruption due to the invalid last component type during do_filp_open()
The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and system crash) via an open system call.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 7 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2014-0203: linux - The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 do...
vendor_debian·2014·CVSS 5.5
CVE-2014-0203 [MEDIUM] CVE-2014-0203: linux - The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 do...
The __do_follow_link function in fs/namei.c in the Linux kernel before 2.6.33 does not properly handle the last pathname component during use of certain filesystems, which allows local users to cause a denial of service (incorrect free operations and system crash) via an open system call.
Scope: local
bookworm: resolved (fixed in 2.6.33-1)
bullseye: resolved (fixed in 2.6.33-1)
forky: resolved (fixed in 2.6.33-1)
sid: resolved (fixed in 2.6.33-1)
trixie: resolved (fixed in 2.6.33-1)
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=86acdca1b63e6890540fa19495cfc708beff3d8bhttp://linux.oracle.com/errata/ELSA-2014-0771.htmlhttp://linux.oracle.com/errata/ELSA-2014-3043.htmlhttp://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.33http://secunia.com/advisories/59262http://secunia.com/advisories/59309http://secunia.com/advisories/59406http://secunia.com/advisories/59560http://www.securityfocus.com/bid/68125https://bugzilla.redhat.com/show_bug.cgi?id=1094363https://github.com/torvalds/linux/commit/86acdca1b63e6890540fa19495cfc708beff3d8bhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=86acdca1b63e6890540fa19495cfc708beff3d8bhttp://linux.oracle.com/errata/ELSA-2014-0771.htmlhttp://linux.oracle.com/errata/ELSA-2014-3043.htmlhttp://mirror.linux.org.au/linux/kernel/v2.6/ChangeLog-2.6.33http://secunia.com/advisories/59262http://secunia.com/advisories/59309http://secunia.com/advisories/59406http://secunia.com/advisories/59560http://www.securityfocus.com/bid/68125https://bugzilla.redhat.com/show_bug.cgi?id=1094363https://github.com/torvalds/linux/commit/86acdca1b63e6890540fa19495cfc708beff3d8b
2014-06-23
Published