CVE-2014-3145
published 2014-05-11CVE-2014-3145: The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.65%
47.4th percentile
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and system crash) via crafted BPF instructions. NOTE: the affected code was moved to the __skb_get_nlattr_nest function before the vulnerability was announced.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 3.14.4-1 (bookworm) | linux 3.14.4-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 3.14.3 | — |
| linux | linux_kernel | >= 0 < 3.14.4-1 | 3.14.4-1 |
| linux | linux_kernel | >= 0 < 3.14.4-1 | 3.14.4-1 |
| linux | linux_kernel | >= 0 < 3.14.4-1 | 3.14.4-1 |
| linux | linux_kernel | >= 0 < 3.14.4-1 | 3.14.4-1 |
| linux | linux_kernel | >= 0 < 3.13.0-32.57 | 3.13.0-32.57 |
| oracle | linux | — | — |
| oracle | linux | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
vendor_ubuntu4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2014-3145: Android Security Bulletin 2017-04-01
CVE: CVE-2014-3145
Severity: HIGH
References: A-34469585
Upstream kernel
[2]
vendor_android·2017-04-01·CVSS 4.9
CVE-2014-3145 [MEDIUM] CVE-2014-3145: Android Security Bulletin 2017-04-01
CVE: CVE-2014-3145
Severity: HIGH
References: A-34469585
Upstream kernel
[2]
Android Security Bulletin 2017-04-01
CVE: CVE-2014-3145
Severity: HIGH
References: A-34469585
Upstream kernel
[2]
Ubuntu
Linux kernel (Raring HWE) vulnerabilities
vendor_ubuntu·2014-07-17·CVSS 2.9
CVE-2014-0131 [LOW] Linux kernel (Raring HWE) vulnerabilities
Title: Linux kernel (Raring HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Michael S. Tsirkin discovered an information leak in the Linux kernel's
segmentation of skbs when using the zerocopy feature of vhost-net. A local
attacker could exploit this flaw to gain potentially sensitive information
from kernel memory. (CVE-2014-0131)
Salva Peiró discovered an information leak in the Linux kernel's media-
device driver. A local attacker could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2014-1739)
A bounds
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-07-17·CVSS 2.1
CVE-2014-1739 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Salva Peiró discovered an information leak in the Linux kernel's media-
device driver. A local attacker could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2014-1739)
A bounds check error was discovered in the socket filter subsystem of the
Linux kernel. A local user could exploit this flaw to cause a denial of
service (system crash) via crafted BPF instructions. (CVE-2014-3144)
A remainder calculation error was discovered in the socket filter
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-07-17·CVSS 2.1
CVE-2014-1739 [LOW] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Salva Peiró discovered an information leak in the Linux kernel's media-
device driver. A local attacker could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2014-1739)
A bounds check error was discovered in the socket filter subsystem of the
Linux kernel. A local user could exploit this flaw to cause a denial of
service (system crash) via crafted BPF instructions. (CVE-2014-3144)
A remainder calculation error was discovered in the
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-06-27·CVSS 2.1
CVE-2014-1739 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Salva Peiró discovered an information leak in the Linux kernel's media-
device driver. A local attacker could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2014-1739)
A bounds check error was discovered in the socket filter subsystem of the
Linux kernel. A local user could exploit this flaw to cause a denial of
service (system crash) via crafted BPF instructions. (CVE-2014-3144)
A remainder calculation error was discovered in the socket filter subsystem
of the Linux kernel. A local user could exploit this flaw to cause a denial
of service (system crash) via crafted BPF instructions. (CVE-2014-3145)
Instructions: After a standard system update you need to reboot y
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-06-27·CVSS 2.1
CVE-2014-1739 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Salva Peiró discovered an information leak in the Linux kernel's media-
device driver. A local attacker could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2014-1739)
A bounds check error was discovered in the socket filter subsystem of the
Linux kernel. A local user could exploit this flaw to cause a denial of
service (system crash) via crafted BPF instructions. (CVE-2014-3144)
A remainder calculation error was discovered in the socket filter subsystem
of the Linux kernel. A local user could exploit this flaw to cause a denial
of service (system crash) via crafted BPF instructions. (CVE-2014-3145)
Instructions: After a standard system update you need to
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2014-06-27·CVSS 4.9
CVE-2014-3144 [MEDIUM] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bounds check error was discovered in the socket filter subsystem of the
Linux kernel. A local user could exploit this flaw to cause a denial of
service (system crash) via crafted BPF instructions. (CVE-2014-3144)
A remainder calculation error was discovered in the socket filter subsystem
of the Linux kernel. A local user could exploit this flaw to cause a denial
of service (system crash) via crafted BPF instructions. (CVE-2014-3145)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile a
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-06-27·CVSS 2.1
CVE-2014-1739 [LOW] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Salva Peiró discovered an information leak in the Linux kernel's media-
device driver. A local attacker could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2014-1739)
A bounds check error was discovered in the socket filter subsystem of the
Linux kernel. A local user could exploit this flaw to cause a denial of
service (system crash) via crafted BPF instructions. (CVE-2014-3144)
A remainder calculation error was discovered in the socket filter subsystem
of the Linux kernel. A local user could exploit this flaw to cause a denial
of service (system crash) via crafted BPF instructions. (CVE-2014-3145)
Instructions: After a standard system update you need
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-06-20·CVSS 4.9
CVE-2014-3144 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bounds check error was discovered in the socket filter subsystem of the
Linux kernel. A local user could exploit this flaw to cause a denial of
service (system crash) via crafted BPF instructions. (CVE-2014-3144)
A remainder calculation error was discovered in the socket filter subsystem
of the Linux kernel. A local user could exploit this flaw to cause a denial
of service (system crash) via crafted BPF instructions. (CVE-2014-3145)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall a
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-06-20·CVSS 4.9
CVE-2014-3144 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A bounds check error was discovered in the socket filter subsystem of the
Linux kernel. A local user could exploit this flaw to cause a denial of
service (system crash) via crafted BPF instructions. (CVE-2014-3144)
A remainder calculation error was discovered in the socket filter subsystem
of the Linux kernel. A local user could exploit this flaw to cause a denial
of service (system crash) via crafted BPF instructions. (CVE-2014-3145)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reins
Red Hat
Kernel: filter: prevent nla extensions to peek beyond the end of the message
vendor_redhat·2014-04-13·CVSS 4.9
CVE-2014-3145 [MEDIUM] Kernel: filter: prevent nla extensions to peek beyond the end of the message
Kernel: filter: prevent nla extensions to peek beyond the end of the message
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and system crash) via crafted BPF instructions. NOTE: the affected code was moved to the __skb_get_nlattr_nest function before the vulnerability was announced.
Statement: This issue does not affect the version of the kernel package as shipped with Red Hat Enterprise Linux 5.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Debian
CVE-2014-3145: linux - The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function...
vendor_debian·2014·CVSS 4.9
CVE-2014-3145 [MEDIUM] CVE-2014-3145: linux - The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function...
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and system crash) via crafted BPF instructions. NOTE: the affected code was moved to the __skb_get_nlattr_nest function before the vulnerability was announced.
Scope: local
bookworm: resolved (fixed in 3.14.4-1)
bullseye: resolved (fixed in 3.14.4-1)
forky: resolved (fixed in 3.14.4-1)
sid: resolved (fixed in 3.14.4-1)
trixie: resolved (fixed in 3.14.4-1)
GHSA
GHSA-j8w5-jmwr-rhqh: The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter
ghsa_unreviewed·2022-05-13
CVE-2014-3145 [MEDIUM] CWE-125 GHSA-j8w5-jmwr-rhqh: The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and system crash) via crafted BPF instructions. NOTE: the affected code was moved to the __skb_get_nlattr_nest function before the vulnerability was announced.
OSV
linux vulnerabilities
osv·2014-07-17·CVSS 2.1
CVE-2014-4943 [LOW] linux vulnerabilities
linux vulnerabilities
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Salva Peiró discovered an information leak in the Linux kernel's media-
device driver. A local attacker could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2014-1739)
A bounds check error was discovered in the socket filter subsystem of the
Linux kernel. A local user could exploit this flaw to cause a denial of
service (system crash) via crafted BPF instructions. (CVE-2014-3144)
A remainder calculation error was discovered in the socket filter subsystem
of the Linux kernel. A local user could exploit this flaw to ca
OSV
CVE-2014-3145: The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter
osv·2014-05-11·CVSS 4.9
CVE-2014-3145 [MEDIUM] CVE-2014-3145: The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter
The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and system crash) via crafted BPF instructions. NOTE: the affected code was moved to the __skb_get_nlattr_nest function before the vulnerability was announced.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3144 CVE-2014-3145 Kernel: filter: prevent nla extensions to peek beyond the end of the message
bugzilla·2014-05-12·CVSS 4.9
CVE-2014-3144 [MEDIUM] CVE-2014-3144 CVE-2014-3145 Kernel: filter: prevent nla extensions to peek beyond the end of the message
CVE-2014-3144 CVE-2014-3145 Kernel: filter: prevent nla extensions to peek beyond the end of the message
Linux kernel built with the BPF interpreter support in the networking core is
vulnerable to an out of bounds buffer access flaw. It occurs when accessing a
netlink attribute from the skb->data buffer. It could lead to DoS via kernel
crash or leakage of kernel memory bytes to user space.
An unprivileged user/program could use this flaw to crash the system kernel
resulting in DoS or leak kernel memory bytes to user space.
Upstream fix:
-> https://git.kernel.org/linus/05ab8f2647e4221cbdb3856dd7d32bd5407316b3
Introduced by:
-> https://git.kernel.org/linus/4738c1db1593687713869fa69e733eebc7b0d6d8
-> https://git.kernel.org/linus/d214c7537bbf2f247991fb65b3420b0b3d712c67
Reference:
-> http
Bugzilla
CVE-2014-3144 CVE-2014-3145 Kernel: filter: prevent nla extensions to peek beyond the end of the message [fedora-all]
bugzilla·2014-05-12·CVSS 4.9
CVE-2014-3144 [MEDIUM] CVE-2014-3144 CVE-2014-3145 Kernel: filter: prevent nla extensions to peek beyond the end of the message [fedora-all]
CVE-2014-3144 CVE-2014-3145 Kernel: filter: prevent nla extensions to peek beyond the end of the message [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when availa
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=05ab8f2647e4221cbdb3856dd7d32bd5407316b3http://linux.oracle.com/errata/ELSA-2014-3052.htmlhttp://secunia.com/advisories/58990http://secunia.com/advisories/59311http://secunia.com/advisories/59597http://secunia.com/advisories/60613http://www.debian.org/security/2014/dsa-2949http://www.openwall.com/lists/oss-security/2014/05/09/6http://www.securityfocus.com/bid/67321http://www.securitytracker.com/id/1038201http://www.ubuntu.com/usn/USN-2251-1http://www.ubuntu.com/usn/USN-2252-1http://www.ubuntu.com/usn/USN-2259-1http://www.ubuntu.com/usn/USN-2261-1http://www.ubuntu.com/usn/USN-2262-1http://www.ubuntu.com/usn/USN-2263-1http://www.ubuntu.com/usn/USN-2264-1https://github.com/torvalds/linux/commit/05ab8f2647e4221cbdb3856dd7d32bd5407316b3https://source.android.com/security/bulletin/2017-04-01http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=05ab8f2647e4221cbdb3856dd7d32bd5407316b3http://linux.oracle.com/errata/ELSA-2014-3052.htmlhttp://secunia.com/advisories/58990http://secunia.com/advisories/59311http://secunia.com/advisories/59597http://secunia.com/advisories/60613http://www.debian.org/security/2014/dsa-2949http://www.openwall.com/lists/oss-security/2014/05/09/6http://www.securityfocus.com/bid/67321http://www.securitytracker.com/id/1038201http://www.ubuntu.com/usn/USN-2251-1http://www.ubuntu.com/usn/USN-2252-1http://www.ubuntu.com/usn/USN-2259-1http://www.ubuntu.com/usn/USN-2261-1http://www.ubuntu.com/usn/USN-2262-1http://www.ubuntu.com/usn/USN-2263-1http://www.ubuntu.com/usn/USN-2264-1https://github.com/torvalds/linux/commit/05ab8f2647e4221cbdb3856dd7d32bd5407316b3https://source.android.com/security/bulletin/2017-04-01
2014-05-11
Published