CVE-2014-2038
published 2014-02-28CVE-2014-2038: The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a…
PriorityP48low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.41%
34.1th percentile
The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memory in opportunistic circumstances by writing to a file in an NFS filesystem and then reading the same file.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 3.13.4-1 (bookworm) | linux 3.13.4-1 (bookworm) |
| linux | linux_kernel | < 3.13.3 | 3.13.3 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_ubuntu2.6LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-03-07·CVSS 2.6
CVE-2014-1690 [LOW] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the Linux kernel when built with the
NetFilter Connection Tracking (NF_CONNTRACK) support for IRC protocol
(NF_NAT_IRC). A remote attacker could exploit this flaw to obtain
potentially sensitive kernel information when communicating over a client-
to-client IRC connection(/dcc) via a NAT-ed network. (CVE-2014-1690)
Matthew Thode reported a denial of service vulnerability in the Linux
kernel when SELinux support is enabled. A local user with the CAP_MAC_ADMIN
capability (and the SELinux mac_admin permission if running in enforcing
mode) could exploit this flaw to cause a denial of service (kernel crash).
(CVE-2014-1874)
An information leak was
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-03-07·CVSS 2.6
CVE-2014-1690 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak was discovered in the Linux kernel when built with the
NetFilter Connection Tracking (NF_CONNTRACK) support for IRC protocol
(NF_NAT_IRC). A remote attacker could exploit this flaw to obtain
potentially sensitive kernel information when communicating over a client-
to-client IRC connection(/dcc) via a NAT-ed network. (CVE-2014-1690)
Matthew Thode reported a denial of service vulnerability in the Linux
kernel when SELinux support is enabled. A local user with the CAP_MAC_ADMIN
capability (and the SELinux mac_admin permission if running in enforcing
mode) could exploit this flaw to cause a denial of service (kernel crash).
(CVE-2014-1874)
An information leak was discovered i
Red Hat
kernel: nfs: data leak during extended writes
vendor_redhat·2014-01-17·CVSS 2.1
CVE-2014-2038 [LOW] kernel: nfs: data leak during extended writes
kernel: nfs: data leak during extended writes
The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memory in opportunistic circumstances by writing to a file in an NFS filesystem and then reading the same file.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2014-2038: linux - The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3...
vendor_debian·2014·CVSS 2.1
CVE-2014-2038 [LOW] CVE-2014-2038: linux - The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3...
The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memory in opportunistic circumstances by writing to a file in an NFS filesystem and then reading the same file.
Scope: local
bookworm: resolved (fixed in 3.13.4-1)
bullseye: resolved (fixed in 3.13.4-1)
forky: resolved (fixed in 3.13.4-1)
sid: resolved (fixed in 3.13.4-1)
trixie: resolved (fixed in 3.13.4-1)
GHSA
GHSA-h2fp-7rxc-44gq: The nfs_can_extend_write function in fs/nfs/write
ghsa_unreviewed·2022-05-13
CVE-2014-2038 [LOW] CWE-200 GHSA-h2fp-7rxc-44gq: The nfs_can_extend_write function in fs/nfs/write
The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memory in opportunistic circumstances by writing to a file in an NFS filesystem and then reading the same file.
OSV
CVE-2014-2038: The nfs_can_extend_write function in fs/nfs/write
osv·2014-02-28·CVSS 2.1
CVE-2014-2038 [LOW] CVE-2014-2038: The nfs_can_extend_write function in fs/nfs/write
The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memory in opportunistic circumstances by writing to a file in an NFS filesystem and then reading the same file.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2038 kernel: nfs: data leak during extended writes
bugzilla·2014-02-19·CVSS 2.1
CVE-2014-2038 [LOW] CVE-2014-2038 kernel: nfs: data leak during extended writes
CVE-2014-2038 kernel: nfs: data leak during extended writes
It was found that cached page was not up-to-date in certain cases when
we were extending write to cover the full page and thus contained
uninitalized data.
A local user with write access to file on nfs share could use this flaw
to leak kernel memory.
Please note that apart from having security consequences (data leak), this
bug is also a data corruptor.
Introduced by:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c7559663
Upstream fix:
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=263b4509
Discussion:
The upstream fix is already backported to the 3.12.11 and 3.13.3 stable kernels. FYI.
---
Statement:
This issue does not affect the versions of the kernel package as
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=263b4509ec4d47e0da3e753f85a39ea12d1eff24http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.13.3http://www.openwall.com/lists/oss-security/2014/02/20/16http://www.ubuntu.com/usn/USN-2137-1http://www.ubuntu.com/usn/USN-2140-1https://bugzilla.redhat.com/show_bug.cgi?id=1066939https://github.com/torvalds/linux/commit/263b4509ec4d47e0da3e753f85a39ea12d1eff24http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=263b4509ec4d47e0da3e753f85a39ea12d1eff24http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.13.3http://www.openwall.com/lists/oss-security/2014/02/20/16http://www.ubuntu.com/usn/USN-2137-1http://www.ubuntu.com/usn/USN-2140-1https://bugzilla.redhat.com/show_bug.cgi?id=1066939https://github.com/torvalds/linux/commit/263b4509ec4d47e0da3e753f85a39ea12d1eff24
2014-02-28
Published