CVE-2014-3182
published 2014-09-28CVE-2014-3182: Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to…
PriorityP427medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.43%
35.3th percentile
Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORT_TYPE_NOTIF_DEVICE_UNPAIRED value.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.2-2 (bookworm) | linux 3.16.2-2 (bookworm) |
| linux | linux_kernel | < 3.2.63 | 3.2.63 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.13.0-39.66 | 3.13.0-39.66 |
| linux | linux_kernel | >= 3.11 < 3.12.28 | 3.12.28 |
| linux | linux_kernel | >= 3.13 < 3.14.18 | 3.14.18 |
| linux | linux_kernel | >= 3.15 < 3.16.2 | 3.16.2 |
| linux | linux_kernel | >= 3.3 < 3.4.104 | 3.4.104 |
| linux | linux_kernel | >= 3.5 < 3.10.54 | 3.10.54 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-63g2-9wjq-ff4j: Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj
ghsa_unreviewed·2022-05-17
CVE-2014-3182 [MEDIUM] CWE-119 GHSA-63g2-9wjq-ff4j: Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj
Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORT_TYPE_NOTIF_DEVICE_UNPAIRED value.
OSV
linux vulnerabilities
osv·2014-10-30·CVSS 6.9
CVE-2014-3647 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
Lars Bull reported a race condition in the PIT (programmable interrupt
timer) emulation in the KVM (Kernel Virtual Machine) subsystem of the Linux
kernel. A local guest user with access to PIT i/o ports could exploit t
OSV
CVE-2014-3182: Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj
osv·2014-09-28·CVSS 6.9
CVE-2014-3182 [MEDIUM] CVE-2014-3182: Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj
Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORT_TYPE_NOTIF_DEVICE_UNPAIRED value.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-30·CVSS 6.9
CVE-2014-3182 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
Lars Bull reported a race condition in the PIT (programmable interrupt
timer) emulation in the KVM (Kernel Virtual Machine) subsystem of the Lin
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-10-30·CVSS 6.9
CVE-2014-3182 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
Lars Bull reported a race condition in the PIT (programmable interrupt
timer) emulation in the KVM (Kernel Virtual Machine) subsyst
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
A bounds check error was discovered in the driver for the Logitech Unifying
receivers and devices. A physically proximate attacker could exploit this
flaw to to cause a denial of service (invalid kfree) or to execute
arbitrary code. (CVE-2014-3182)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a deni
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
A bounds check error was discovered in the driver for the Logitech Unifying
receivers and devices. A physically proximate attacker could exploit this
flaw to to cause a denial of service (invalid kfree) or to execute
arbitrary code. (CVE-2014-3182)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to caus
Red Hat
Kernel: HID: logitech-dj OOB array access
vendor_redhat·2014-08-21·CVSS 6.9
CVE-2014-3182 [MEDIUM] Kernel: HID: logitech-dj OOB array access
Kernel: HID: logitech-dj OOB array access
Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORT_TYPE_NOTIF_DEVICE_UNPAIRED value.
An out-of-bounds read flaw was found in the way the Logitech Unifying receiver driver handled HID reports with an invalid device_index value. An attacker with physical access to the system could use this flaw to crash the system or, potentially, escalate their privileges on the system.
Statement: This issue does not affect the version of the kernel package as shipped with
Red Hat Enterprise Linux 5 and 6.
This issue affects the version
Debian
CVE-2014-3182: linux - Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-...
vendor_debian·2014·CVSS 6.9
CVE-2014-3182 [MEDIUM] CVE-2014-3182: linux - Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-...
Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORT_TYPE_NOTIF_DEVICE_UNPAIRED value.
Scope: local
bookworm: resolved (fixed in 3.16.2-2)
bullseye: resolved (fixed in 3.16.2-2)
forky: resolved (fixed in 3.16.2-2)
sid: resolved (fixed in 3.16.2-2)
trixie: resolved (fixed in 3.16.2-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3182 Kernel: HID: logitech-dj OOB array access [fedora-all]
bugzilla·2014-09-12·CVSS 6.9
CVE-2014-3182 [MEDIUM] CVE-2014-3182 Kernel: HID: logitech-dj OOB array access [fedora-all]
CVE-2014-3182 Kernel: HID: logitech-dj OOB array access [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. W
Bugzilla
CVE-2014-3182 Kernel: HID: logitech-dj OOB array access
bugzilla·2014-09-12·CVSS 6.9
CVE-2014-3182 [MEDIUM] CVE-2014-3182 Kernel: HID: logitech-dj OOB array access
CVE-2014-3182 Kernel: HID: logitech-dj OOB array access
Linux kernel built with the Human Interface Device(HID) Bus support(CONFIG_HID)
along with a Logitech Unifying receivers full support(CONFIG_HID_LOGITECH_DJ)
driver, is vulnerable to an OOB read flaw. It could occur if a device offers
a malicious HID report with arbitrary device_index.
A local user with physical access to the system could use this flaw to crash
the system resulting in DoS.
Upstream fix:
-> https://git.kernel.org/linus/ad3e14d7c5268c2e24477c6ef54bbdf88add5d36
Discussion:
Statement:
This issue does not affect the version of the kernel package as shipped with
Red Hat Enterprise Linux 5 and 6.
This issue affects the versions of Linux kernel as shipped with Red Hat Enterprise Linux 7 and Red Hat Enterprise MRG 2. Fu
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ad3e14d7c5268c2e24477c6ef54bbdf88add5d36http://rhn.redhat.com/errata/RHSA-2014-1318.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.16.2http://www.openwall.com/lists/oss-security/2014/09/11/21http://www.securityfocus.com/bid/69770https://bugzilla.redhat.com/show_bug.cgi?id=1141210https://code.google.com/p/google-security-research/issues/detail?id=89https://github.com/torvalds/linux/commit/ad3e14d7c5268c2e24477c6ef54bbdf88add5d36http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ad3e14d7c5268c2e24477c6ef54bbdf88add5d36http://rhn.redhat.com/errata/RHSA-2014-1318.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.16.2http://www.openwall.com/lists/oss-security/2014/09/11/21http://www.securityfocus.com/bid/69770https://bugzilla.redhat.com/show_bug.cgi?id=1141210https://code.google.com/p/google-security-research/issues/detail?id=89https://github.com/torvalds/linux/commit/ad3e14d7c5268c2e24477c6ef54bbdf88add5d36
2014-09-28
Published