CVE-2014-3186
published 2014-09-28CVE-2014-3186: Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as…
PriorityP430medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.70%
49.7th percentile
Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that sends a large report.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 3.16.5-1 (bookworm) | linux 3.16.5-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.16.5-1 | 3.16.5-1 |
| linux | linux_kernel | >= 0 < 3.16.5-1 | 3.16.5-1 |
| linux | linux_kernel | >= 0 < 3.16.5-1 | 3.16.5-1 |
| linux | linux_kernel | >= 0 < 3.16.5-1 | 3.16.5-1 |
| linux | linux_kernel | >= 0 < 3.13.0-37.64 | 3.13.0-37.64 |
| linux | linux_kernel | >= 2.6.35 < 3.2.63 | 3.2.63 |
| linux | linux_kernel | >= 3.11 < 3.12.31 | 3.12.31 |
| linux | linux_kernel | >= 3.13 < 3.14.20 | 3.14.20 |
| linux | linux_kernel | >= 3.15 < 3.16.4 | 3.16.4 |
| linux | linux_kernel | >= 3.3 < 3.4.104 | 3.4.104 |
| linux | linux_kernel | >= 3.5 < 3.10.56 | 3.10.56 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attac
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
A bounds check error was discovered in the driver for the Logitech Unifying
receivers and devices. A physically proximate attacker could exploit this
flaw to to cause a denial of service (invalid kfree) or to execute
arbitrary code. (CVE-2014-3182)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a deni
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
A bounds check error was discovered in the driver for the Logitech Unifying
receivers and devices. A physically proximate attacker could exploit this
flaw to to cause a denial of service (invalid kfree) or to execute
arbitrary code. (CVE-2014-3182)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to caus
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attacker could exp
Red Hat
Kernel: HID: memory corruption via OOB write
vendor_redhat·2014-08-27·CVSS 6.9
CVE-2014-3186 [MEDIUM] CWE-787 Kernel: HID: memory corruption via OOB write
Kernel: HID: memory corruption via OOB write
Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that sends a large report.
A buffer overflow flaw was found in the way the Minibox PicoLCD driver handled Human Interface Device (HID) reports with an invalid size. An attacker with physical access to the system could use this flaw to crash the system or, potentially, escalate their privileges on the system.
Statement: This issue does not affect the versions of Linux kernel as shipped with
Red Hat Enterprise Linux 5, 6
Debian
CVE-2014-3186: linux - Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_cor...
vendor_debian·2014·CVSS 6.9
CVE-2014-3186 [MEDIUM] CVE-2014-3186: linux - Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_cor...
Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that sends a large report.
Scope: local
bookworm: resolved (fixed in 3.16.5-1)
bullseye: resolved (fixed in 3.16.5-1)
forky: resolved (fixed in 3.16.5-1)
sid: resolved (fixed in 3.16.5-1)
trixie: resolved (fixed in 3.16.5-1)
GHSA
GHSA-cg5g-vw88-93vq: Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core
ghsa_unreviewed·2022-05-17
CVE-2014-3186 [MEDIUM] CWE-119 GHSA-cg5g-vw88-93vq: Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core
Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that sends a large report.
OSV
linux vulnerabilities
osv·2014-10-09·CVSS 6.9
CVE-2014-3181 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Steven Vittitoe reported multiple stack buffer overflows in Linux kernel's
magicmouse HID driver. A physically proximate attacker could exploit this
flaw to cause a denial of service (system crash) or possibly execute
arbitrary code via specially crafted devices. (CVE-2014-3181)
Ben Hawkes reported some off by one errors for report descriptors in the
Linux kernel's HID stack. A physically proximate attacker could exploit
these flaws to cause a denial of service (out-of-bounds write) via a
specially crafted device. (CVE-2014-3184)
Several bounds check flaws allowing for buffer overflows were discovered in
the Linux kernel's Whiteheat USB serial driver. A physically proximate
attacker could exploit these flaws to cause a denial of service (system
crash) via a special
OSV
CVE-2014-3186: Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core
osv·2014-09-28·CVSS 6.9
CVE-2014-3186 [MEDIUM] CVE-2014-3186: Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core
Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that sends a large report.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3186 Kernel: HID: memory corruption via OOB write
bugzilla·2014-09-13·CVSS 6.9
CVE-2014-3186 [MEDIUM] CVE-2014-3186 Kernel: HID: memory corruption via OOB write
CVE-2014-3186 Kernel: HID: memory corruption via OOB write
Linux kernel built with the Human Interface Device(HID) Bus support(CONFIG_HID)
along with a driver for Minibox PicoLCD devices support(CONFIG_HID_PICOLCD),
is vulnerable to an OOB write flaw. It could occur if a device offers an HID
report with arbitrary(>64) data size value.
A local user with physical access to the system could use this flaw to crash
the system resulting in DoS or potentially, escalate their privileges on the
system.
Upstream fix:
-> https://git.kernel.org/linus/844817e47eef14141cf59b8d5ac08dd11c0a9189
Reference:
-> http://www.openwall.com/lists/oss-security/2014/09/11/22
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1141410]
---
Statement:
This issue does not affect
Bugzilla
CVE-2014-3186 Kernel: HID: memory corruption via OOB write [fedora-all]
bugzilla·2014-09-13·CVSS 6.9
CVE-2014-3186 [MEDIUM] CVE-2014-3186 Kernel: HID: memory corruption via OOB write [fedora-all]
CVE-2014-3186 Kernel: HID: memory corruption via OOB write [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=844817e47eef14141cf59b8d5ac08dd11c0a9189http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://www.openwall.com/lists/oss-security/2014/09/11/22http://www.securityfocus.com/bid/69763http://www.ubuntu.com/usn/USN-2376-1http://www.ubuntu.com/usn/USN-2377-1http://www.ubuntu.com/usn/USN-2378-1http://www.ubuntu.com/usn/USN-2379-1https://bugzilla.redhat.com/show_bug.cgi?id=1141407https://code.google.com/p/google-security-research/issues/detail?id=101https://github.com/torvalds/linux/commit/844817e47eef14141cf59b8d5ac08dd11c0a9189http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=844817e47eef14141cf59b8d5ac08dd11c0a9189http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://www.openwall.com/lists/oss-security/2014/09/11/22http://www.securityfocus.com/bid/69763http://www.ubuntu.com/usn/USN-2376-1http://www.ubuntu.com/usn/USN-2377-1http://www.ubuntu.com/usn/USN-2378-1http://www.ubuntu.com/usn/USN-2379-1https://bugzilla.redhat.com/show_bug.cgi?id=1141407https://code.google.com/p/google-security-research/issues/detail?id=101https://github.com/torvalds/linux/commit/844817e47eef14141cf59b8d5ac08dd11c0a9189
2014-09-28
Published