CVE-2014-3184
published 2014-09-28CVE-2014-3184: The report_fixup functions in the HID subsystem in the Linux kernel before 3.16.2 might allow physically proximate attackers to cause a denial of service…
PriorityP418medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.40%
32.6th percentile
The report_fixup functions in the HID subsystem in the Linux kernel before 3.16.2 might allow physically proximate attackers to cause a denial of service (out-of-bounds write) via a crafted device that provides a small report descriptor, related to (1) drivers/hid/hid-cherry.c, (2) drivers/hid/hid-kye.c, (3) drivers/hid/hid-lg.c, (4) drivers/hid/hid-monterey.c, (5) drivers/hid/hid-petalynx.c, and (6) drivers/hid/hid-sunplus.c.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.2-2 (bookworm) | linux 3.16.2-2 (bookworm) |
| linux | linux_kernel | <= 3.16.1 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.16.2-2 | 3.16.2-2 |
| linux | linux_kernel | >= 0 < 3.13.0-37.64 | 3.13.0-37.64 |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv6.9MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attac
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
A bounds check error was discovered in the driver for the Logitech Unifying
receivers and devices. A physically proximate attacker could exploit this
flaw to to cause a denial of service (invalid kfree) or to execute
arbitrary code. (CVE-2014-3182)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a deni
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 4.7
CVE-2014-3184 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attacker could exploit these flaws to cause a denial of service (system
crash) via a specially crafted device. (CVE-2014-3185)
A flaw was discovered in the Linux kernel's UDF filesystem (used on some
CD-ROMs and DVDs) when processing indirect ICBs. An attacker who can cause
CD, DVD or image file w
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
A bounds check error was discovered in the driver for the Logitech Unifying
receivers and devices. A physically proximate attacker could exploit this
flaw to to cause a denial of service (invalid kfree) or to execute
arbitrary code. (CVE-2014-3182)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to caus
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attacker could exp
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 4.7
CVE-2014-3184 [MEDIUM] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attacker could exploit these flaws to cause a denial of service (system
crash) via a specially crafted device. (CVE-2014-3185)
A flaw was discovered in the Linux kernel's UDF filesystem (used on some
CD-ROMs and DVDs) when processing indirect ICBs. An attacker who can cause
CD, DVD or image
Red Hat
Kernel: HID: off by one error in various _report_fixup routines
vendor_redhat·2014-08-21·CVSS 4.7
CVE-2014-3184 [MEDIUM] CWE-193 Kernel: HID: off by one error in various _report_fixup routines
Kernel: HID: off by one error in various _report_fixup routines
The report_fixup functions in the HID subsystem in the Linux kernel before 3.16.2 might allow physically proximate attackers to cause a denial of service (out-of-bounds write) via a crafted device that provides a small report descriptor, related to (1) drivers/hid/hid-cherry.c, (2) drivers/hid/hid-kye.c, (3) drivers/hid/hid-lg.c, (4) drivers/hid/hid-monterey.c, (5) drivers/hid/hid-petalynx.c, and (6) drivers/hid/hid-sunplus.c.
Multiple out-of-bounds write flaws were found in the way the Cherry Cymotion keyboard driver, KYE/Genius device drivers, Logitech device drivers, Monterey Genius KB29E keyboard driver, Petalynx Maxter remote control driver, and Sunplus wireless desktop driver handled HID reports with an invalid report
Debian
CVE-2014-3184: linux - The report_fixup functions in the HID subsystem in the Linux kernel before 3.16....
vendor_debian·2014·CVSS 4.7
CVE-2014-3184 [MEDIUM] CVE-2014-3184: linux - The report_fixup functions in the HID subsystem in the Linux kernel before 3.16....
The report_fixup functions in the HID subsystem in the Linux kernel before 3.16.2 might allow physically proximate attackers to cause a denial of service (out-of-bounds write) via a crafted device that provides a small report descriptor, related to (1) drivers/hid/hid-cherry.c, (2) drivers/hid/hid-kye.c, (3) drivers/hid/hid-lg.c, (4) drivers/hid/hid-monterey.c, (5) drivers/hid/hid-petalynx.c, and (6) drivers/hid/hid-sunplus.c.
Scope: local
bookworm: resolved (fixed in 3.16.2-2)
bullseye: resolved (fixed in 3.16.2-2)
forky: resolved (fixed in 3.16.2-2)
sid: resolved (fixed in 3.16.2-2)
trixie: resolved (fixed in 3.16.2-2)
GHSA
GHSA-8p53-rhxf-cgxv: The report_fixup functions in the HID subsystem in the Linux kernel before 3
ghsa_unreviewed·2022-05-17
CVE-2014-3184 [MEDIUM] CWE-119 GHSA-8p53-rhxf-cgxv: The report_fixup functions in the HID subsystem in the Linux kernel before 3
The report_fixup functions in the HID subsystem in the Linux kernel before 3.16.2 might allow physically proximate attackers to cause a denial of service (out-of-bounds write) via a crafted device that provides a small report descriptor, related to (1) drivers/hid/hid-cherry.c, (2) drivers/hid/hid-kye.c, (3) drivers/hid/hid-lg.c, (4) drivers/hid/hid-monterey.c, (5) drivers/hid/hid-petalynx.c, and (6) drivers/hid/hid-sunplus.c.
OSV
linux vulnerabilities
osv·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attacker could exploit these flaws to cause a denial of service (system
crash) via a special
OSV
CVE-2014-3184: The report_fixup functions in the HID subsystem in the Linux kernel before 3
osv·2014-09-28·CVSS 4.7
CVE-2014-3184 [MEDIUM] CVE-2014-3184: The report_fixup functions in the HID subsystem in the Linux kernel before 3
The report_fixup functions in the HID subsystem in the Linux kernel before 3.16.2 might allow physically proximate attackers to cause a denial of service (out-of-bounds write) via a crafted device that provides a small report descriptor, related to (1) drivers/hid/hid-cherry.c, (2) drivers/hid/hid-kye.c, (3) drivers/hid/hid-lg.c, (4) drivers/hid/hid-monterey.c, (5) drivers/hid/hid-petalynx.c, and (6) drivers/hid/hid-sunplus.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3184 Kernel: HID: off by one error in various _report_fixup routines
bugzilla·2014-09-13·CVSS 4.7
CVE-2014-3184 [MEDIUM] CVE-2014-3184 Kernel: HID: off by one error in various _report_fixup routines
CVE-2014-3184 Kernel: HID: off by one error in various _report_fixup routines
Linux kernel built with the Human Interface Device(HID) Bus support(CONFIG_HID)
along with a driver for
Cherry Cymotion keyboard support(CONFIG_HID_CHERRY)
KYE/Genius devices support(CONFIG_HID_KYE)
Logitech devices support(CONFIG_HID_LOGITECH)
Monterey Genius KB29E keyboard support(CONFIG_HID_MONTEREY)
Petalynx Maxter remote control support(CONFIG_HID_PETALYNX)
Sunplus wireless desktop support(CONFIG_HID_SUNPLUS)
is vulnerable to an OOB write flaw. It could occur if an HID device report
offers an invalid report descriptor size.
A local user with physical access to the system could use this flaw to write
past an allocated memory buffer. This is mostly a non issue as the allocated
memory buffer comes with the
Bugzilla
CVE-2014-3184 Kernel: HID: off by one error in various _report_fixup routines [fedora-all]
bugzilla·2014-09-13·CVSS 4.7
CVE-2014-3184 [MEDIUM] CVE-2014-3184 Kernel: HID: off by one error in various _report_fixup routines [fedora-all]
CVE-2014-3184 Kernel: HID: off by one error in various _report_fixup routines [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4ab25786c87eb20857bbb715c3ae34ec8fd6a214http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1318.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1272.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.16.2http://www.openwall.com/lists/oss-security/2014/09/11/21http://www.securityfocus.com/bid/69768http://www.ubuntu.com/usn/USN-2374-1http://www.ubuntu.com/usn/USN-2375-1http://www.ubuntu.com/usn/USN-2376-1http://www.ubuntu.com/usn/USN-2377-1http://www.ubuntu.com/usn/USN-2378-1http://www.ubuntu.com/usn/USN-2379-1https://bugzilla.redhat.com/show_bug.cgi?id=1141391https://code.google.com/p/google-security-research/issues/detail?id=91https://github.com/torvalds/linux/commit/4ab25786c87eb20857bbb715c3ae34ec8fd6a214http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4ab25786c87eb20857bbb715c3ae34ec8fd6a214http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1318.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1272.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.16.2http://www.openwall.com/lists/oss-security/2014/09/11/21http://www.securityfocus.com/bid/69768http://www.ubuntu.com/usn/USN-2374-1http://www.ubuntu.com/usn/USN-2375-1http://www.ubuntu.com/usn/USN-2376-1http://www.ubuntu.com/usn/USN-2377-1http://www.ubuntu.com/usn/USN-2378-1http://www.ubuntu.com/usn/USN-2379-1https://bugzilla.redhat.com/show_bug.cgi?id=1141391https://code.google.com/p/google-security-research/issues/detail?id=91https://github.com/torvalds/linux/commit/4ab25786c87eb20857bbb715c3ae34ec8fd6a214
2014-09-28
Published