CVE-2014-2039
published 2014-02-28CVE-2014-2039: arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform does not properly handle attempted use of the linkage stack, which allows…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.46%
37.6th percentile
arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform does not properly handle attempted use of the linkage stack, which allows local users to cause a denial of service (system crash) by executing a crafted instruction.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.13.5-1 (bookworm) | linux 3.13.5-1 (bookworm) |
| linux | linux_kernel | < 3.13.5 | 3.13.5 |
| linux | linux_kernel | >= 0 < 3.13.5-1 | 3.13.5-1 |
| linux | linux_kernel | >= 0 < 3.13.5-1 | 3.13.5-1 |
| linux | linux_kernel | >= 0 < 3.13.5-1 | 3.13.5-1 |
| linux | linux_kernel | >= 0 < 3.13.5-1 | 3.13.5-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
Kernel: s390: crash due to linkage stack instructions
vendor_redhat·2014-02-03·CVSS 4.9
CVE-2014-2039 [MEDIUM] Kernel: s390: crash due to linkage stack instructions
Kernel: s390: crash due to linkage stack instructions
arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform does not properly handle attempted use of the linkage stack, which allows local users to cause a denial of service (system crash) by executing a crafted instruction.
Statement: This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2. Red Hat Enterprise Linux 7 is not affected by this CVE because the fix was included at 7.0 GA (General Availability).
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2014-2039: linux - arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform...
vendor_debian·2014·CVSS 4.9
CVE-2014-2039 [MEDIUM] CVE-2014-2039: linux - arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform...
arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform does not properly handle attempted use of the linkage stack, which allows local users to cause a denial of service (system crash) by executing a crafted instruction.
Scope: local
bookworm: resolved (fixed in 3.13.5-1)
bullseye: resolved (fixed in 3.13.5-1)
forky: resolved (fixed in 3.13.5-1)
sid: resolved (fixed in 3.13.5-1)
trixie: resolved (fixed in 3.13.5-1)
GHSA
GHSA-v8xh-4w6f-jvx2: arch/s390/kernel/head64
ghsa_unreviewed·2022-05-13
CVE-2014-2039 [MEDIUM] CWE-20 GHSA-v8xh-4w6f-jvx2: arch/s390/kernel/head64
arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform does not properly handle attempted use of the linkage stack, which allows local users to cause a denial of service (system crash) by executing a crafted instruction.
OSV
CVE-2014-2039: arch/s390/kernel/head64
osv·2014-02-28·CVSS 4.9
CVE-2014-2039 [MEDIUM] CVE-2014-2039: arch/s390/kernel/head64
arch/s390/kernel/head64.S in the Linux kernel before 3.13.5 on the s390 platform does not properly handle attempted use of the linkage stack, which allows local users to cause a denial of service (system crash) by executing a crafted instruction.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2039 Kernel: s390: crash due to linkage stack instructions [fedora-all]
bugzilla·2014-02-21·CVSS 4.9
CVE-2014-2039 [MEDIUM] CVE-2014-2039 Kernel: s390: crash due to linkage stack instructions [fedora-all]
CVE-2014-2039 Kernel: s390: crash due to linkage stack instructions [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
Please note: this issue
Bugzilla
CVE-2014-2039 Kernel: s390: crash due to linkage stack instructions
bugzilla·2014-02-20·CVSS 4.9
CVE-2014-2039 [MEDIUM] CVE-2014-2039 Kernel: s390: crash due to linkage stack instructions
CVE-2014-2039 Kernel: s390: crash due to linkage stack instructions
Linux kernel built for the s390 architecture(CONFIG_S390) is vulnerable to a
crash due to low-address protection exception. It occurs when an application
uses a linkage stack instruction.
An unprivileged user/application could use this flaw to crash the system
resulting in DoS.
Upstream fix:
-> https://git.kernel.org/linus/8d7f6690cedb83456edd41c9bd583783f0703bf0
Discussion:
Statement:
This issue does not affect the versions of the kernel package as shipped with Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1068758]
---
kernel-3.13.5-200.fc20 has been pushed to the Fedora 20 stable repository. If problems still persist, please m
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8d7f6690cedb83456edd41c9bd583783f0703bf0http://linux.oracle.com/errata/ELSA-2014-0771.htmlhttp://secunia.com/advisories/59262http://secunia.com/advisories/59309http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.13.5http://www.openwall.com/lists/oss-security/2014/02/20/14http://www.securityfocus.com/bid/65700https://bugzilla.redhat.com/show_bug.cgi?id=1067558https://github.com/torvalds/linux/commit/8d7f6690cedb83456edd41c9bd583783f0703bf0http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=8d7f6690cedb83456edd41c9bd583783f0703bf0http://linux.oracle.com/errata/ELSA-2014-0771.htmlhttp://secunia.com/advisories/59262http://secunia.com/advisories/59309http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.13.5http://www.openwall.com/lists/oss-security/2014/02/20/14http://www.securityfocus.com/bid/65700https://bugzilla.redhat.com/show_bug.cgi?id=1067558https://github.com/torvalds/linux/commit/8d7f6690cedb83456edd41c9bd583783f0703bf0
2014-02-28
Published