CVE-2014-2568
published 2014-03-24CVE-2014-2568: Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain…
PriorityP411low2.9CVSS 2.0
AVAACMAuNCPINAN
EPSS
1.01%
59.9th percentile
Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. NOTE: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vulnerability was announced.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 3.13.7-1 (bookworm) | linux 3.13.7-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.13.7-1 | 3.13.7-1 |
| linux | linux_kernel | >= 0 < 3.13.7-1 | 3.13.7-1 |
| linux | linux_kernel | >= 0 < 3.13.7-1 | 3.13.7-1 |
| linux | linux_kernel | >= 0 < 3.13.7-1 | 3.13.7-1 |
| linux | linux_kernel | >= 0 < 3.13.0-29.53 | 3.13.0-29.53 |
| linux | linux_kernel | 3.0 – 3.13.6 | — |
CVSS provenance
nvdv2.02.9LOWAV:A/AC:M/Au:N/C:P/I:N/A:N
osv2.9LOW
vendor_ubuntu5.5MEDIUM
vendor_debian2.9LOW
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-06-27·CVSS 5.5
CVE-2014-0077 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's pseudo tty (pty) device. An
unprivileged user could exploit this flaw to cause a denial of service
(system crash) or potentially gain administrator privileges.
(CVE-2014-0196)
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
An information leak was discovered in the netfilter subsystem of the Linux
kernel. An attacker could exploit this flaw to obtain sensitive information
from kernel memory. (CVE-2014-2568)
Sasha Levin reported a bug in the Linux kernel's virtual memory management
subs
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 2.9
CVE-2014-2568 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
An information leak was discovered in the netfilter subsystem of the Linux
kernel. An attacker could exploit this flaw to obtain sensitive information
from kernel memory. (CVE-2014-2568)
Sasha Levin reported a bug in the Linux kernel's virtual memory management
subsystem. An unprivileged local user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-3122)
Instructions: After a standard system update you need to reboot your computer to make
all the necessa
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
An information leak was discovered in the netfilter subsystem of the Linux
kernel. An attacker could exploit this flaw to obtain sensitive information
from kernel memory. (CVE-2014-2568)
Sasha Levin reported a bug in the Linux kernel's virtual memory management
subsystem. An un
Red Hat
kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied
vendor_redhat·2014-03-18·CVSS 2.9
CVE-2014-2568 [LOW] kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied
kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied
Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. NOTE: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vulnerability was announced.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: realtime-kernel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2014-2568: linux - Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetl...
vendor_debian·2014·CVSS 2.9
CVE-2014-2568 [LOW] CVE-2014-2568: linux - Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetl...
Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. NOTE: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vulnerability was announced.
Scope: local
bookworm: resolved (fixed in 3.13.7-1)
bullseye: resolved (fixed in 3.13.7-1)
forky: resolved (fixed in 3.13.7-1)
sid: resolved (fixed in 3.13.7-1)
trixie: resolved (fixed in 3.13.7-1)
VulDB
Linux Kernel 3.14-rc7 nfnetlink_queue_core.c skb_zerocopy resource management (Nessus ID 74360 / ID 168480)
vuldb·2026-05-08·CVSS 2.9
CVE-2014-2568 [LOW] Linux Kernel 3.14-rc7 nfnetlink_queue_core.c skb_zerocopy resource management (Nessus ID 74360 / ID 168480)
A vulnerability was found in Linux Kernel 3.14-rc7. It has been classified as problematic. This vulnerability affects the function skb_zerocopy of the file net/netfilter/nfnetlink_queue_core.c. Performing a manipulation results in improper resource management.
This vulnerability is known as CVE-2014-2568. Attacking locally is a requirement. No exploit is available.
To fix this issue, it is recommended to deploy a patch.
GHSA
GHSA-wcjr-fm9w-6wrp: Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core
ghsa_unreviewed·2022-05-14
CVE-2014-2568 [LOW] CWE-416 GHSA-wcjr-fm9w-6wrp: Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core
Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. NOTE: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vulnerability was announced.
OSV
linux vulnerabilities
osv·2014-06-05·CVSS 2.9
CVE-2014-3153 [LOW] linux vulnerabilities
linux vulnerabilities
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
An information leak was discovered in the netfilter subsystem of the Linux
kernel. An attacker could exploit this flaw to obtain sensitive information
from kernel memory. (CVE-2014-2568)
Sasha Levin reported a bug in the Linux kernel's virtual memory management
subsystem. An unprivileged local user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-3122)
OSV
CVE-2014-2568: Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core
osv·2014-03-24·CVSS 2.9
CVE-2014-2568 [LOW] CVE-2014-2568: Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core
Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. NOTE: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vulnerability was announced.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-2568 kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied [fedora-all]
bugzilla·2014-03-20·CVSS 2.9
CVE-2014-2568 [LOW] CVE-2014-2568 kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied [fedora-all]
CVE-2014-2568 kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, please use the bodhi submission link
noted in the next comment(s). This will include the bug IDs of this
tracking bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availa
Bugzilla
CVE-2014-2568 kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied
bugzilla·2014-03-20·CVSS 2.9
CVE-2014-2568 [LOW] CVE-2014-2568 kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied
CVE-2014-2568 kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied
An information leak flaw was found in the way skb_zerocopy() copied skbs that are backed by userspace buffers (for example vhost-net and recent xen netback). Once the source skb is consumed, ubuf destructor is called and potentially releases the corresponding userspace buffers, which can then for example be repurposed, while the destination skb is still pointing to the them.
Upstream patch:
https://lkml.org/lkml/2014/3/20/421
Discussion:
Statement:
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1079013]
---
MITRE assigned CVE-2014
http://seclists.org/oss-sec/2014/q1/627http://secunia.com/advisories/59599http://www.openwall.com/lists/oss-security/2014/03/20/16http://www.securityfocus.com/bid/66348http://www.ubuntu.com/usn/USN-2240-1https://bugzilla.redhat.com/show_bug.cgi?id=1079012https://exchange.xforce.ibmcloud.com/vulnerabilities/91922https://lkml.org/lkml/2014/3/20/421http://seclists.org/oss-sec/2014/q1/627http://secunia.com/advisories/59599http://www.openwall.com/lists/oss-security/2014/03/20/16http://www.securityfocus.com/bid/66348http://www.ubuntu.com/usn/USN-2240-1https://bugzilla.redhat.com/show_bug.cgi?id=1079012https://exchange.xforce.ibmcloud.com/vulnerabilities/91922https://lkml.org/lkml/2014/3/20/421
2014-03-24
Published