CVE-2014-2678NULL Pointer Dereference in Kernel

Severity
4.7MEDIUMNVD
EPSS
0.1%
top 74.23%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedApr 1
Latest updateMay 13

Description

The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a bind system call for an RDS socket on a system that lacks RDS transports.

CVSS vector

AV:L/AC:M/C:N/I:N/A:CExploitability: 3.4 | Impact: 6.9

Affected Packages3 packages

Debianlinux/linux_kernel< 3.13.10-1+3

Also affects: Fedora 20

Patches

🔴Vulnerability Details

3
GHSA
GHSA-m6m4-ppmj-ppv3: The rds_iw_laddr_check function in net/rds/iw2022-05-13
OSV
CVE-2014-2678: The rds_iw_laddr_check function in net/rds/iw2014-04-01
CVEList
CVE-2014-2678: The rds_iw_laddr_check function in net/rds/iw2014-04-01

📋Vendor Advisories

10
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities2014-05-27
Ubuntu
Linux kernel (OMAP4) vulnerabilities2014-05-27
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities2014-05-27
Ubuntu
Linux kernel vulnerabilities2014-05-27
Ubuntu
Linux kernel (Raring HWE) vulnerabilities2014-05-27

💬Community

2
Bugzilla
CVE-2014-2678 kernel: net: rds: dereference of a NULL device in rds_iw_laddr_check()2014-04-01
Bugzilla
CVE-2014-2678 kernel: net: rds: dereference of a NULL device in rds_iw_laddr_check() [fedora-all]2014-04-01
CVE-2014-2678 — NULL Pointer Dereference in Kernel | cvebase