CVE-2014-3940
published 2014-06-05CVE-2014-3940: The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory…
PriorityP414medium4CVSS 2.0
AVLACHAuNCNINAC
EPSS
0.27%
19.3th percentile
The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.c and mm/mempolicy.c.
Affected
14 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.14.7-1 (bookworm) | linux 3.14.7-1 (bookworm) |
| linux | linux_kernel | <= 3.14.5 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.14.7-1 | 3.14.7-1 |
| linux | linux_kernel | >= 0 < 3.14.7-1 | 3.14.7-1 |
| linux | linux_kernel | >= 0 < 3.14.7-1 | 3.14.7-1 |
| linux | linux_kernel | >= 0 < 3.14.7-1 | 3.14.7-1 |
| linux | linux_kernel | >= 0 < 3.13.0-32.57 | 3.13.0-32.57 |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv2.04.0MEDIUMAV:L/AC:H/Au:N/C:N/I:N/A:C
osv4.0MEDIUM
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-07-17·CVSS 2.1
CVE-2014-1739 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Salva Peiró discovered an information leak in the Linux kernel's media-
device driver. A local attacker could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2014-1739)
A bounds check error was discovered in the socket filter subsystem of the
Linux kernel. A local user could exploit this flaw to cause a denial of
service (system crash) via crafted BPF instructions. (CVE-2014-3144)
A remainder calculation error was discovered in the socket filter
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-07-17·CVSS 2.1
CVE-2014-1739 [LOW] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Salva Peiró discovered an information leak in the Linux kernel's media-
device driver. A local attacker could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2014-1739)
A bounds check error was discovered in the socket filter subsystem of the
Linux kernel. A local user could exploit this flaw to cause a denial of
service (system crash) via crafted BPF instructions. (CVE-2014-3144)
A remainder calculation error was discovered in the
Red Hat
Kernel: missing check during hugepage migration
vendor_redhat·2014-03-18·CVSS 4.0
CVE-2014-3940 [MEDIUM] Kernel: missing check during hugepage migration
Kernel: missing check during hugepage migration
The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.c and mm/mempolicy.c.
A flaw was found in the way Linux kernel's Transparent Huge Pages (THP) implementation handled non-huge page migration. A local, unprivileged user could use this flaw to crash the kernel by migrating transparent hugepages.
Statement: This issue did not affect the version of the kernel package as shipped with
Red Hat Enterprise Linux 5.
Package: kernel (Red Hat Enterprise
Debian
CVE-2014-3940: linux - The Linux kernel through 3.14.5 does not properly consider the presence of huget...
vendor_debian·2014·CVSS 4.0
CVE-2014-3940 [MEDIUM] CVE-2014-3940: linux - The Linux kernel through 3.14.5 does not properly consider the presence of huget...
The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.c and mm/mempolicy.c.
Scope: local
bookworm: resolved (fixed in 3.14.7-1)
bullseye: resolved (fixed in 3.14.7-1)
forky: resolved (fixed in 3.14.7-1)
sid: resolved (fixed in 3.14.7-1)
trixie: resolved (fixed in 3.14.7-1)
GHSA
GHSA-pp3m-vq48-qr56: The Linux kernel through 3
ghsa_unreviewed·2022-05-13
CVE-2014-3940 [MEDIUM] CWE-362 GHSA-pp3m-vq48-qr56: The Linux kernel through 3
The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.c and mm/mempolicy.c.
OSV
linux vulnerabilities
osv·2014-07-17·CVSS 2.1
CVE-2014-4943 [LOW] linux vulnerabilities
linux vulnerabilities
Sasha Levin reported a flaw in the Linux kernel's point-to-point protocol
(PPP) when used with the Layer Two Tunneling Protocol (L2TP). A local user
could exploit this flaw to gain administrative privileges. (CVE-2014-4943)
Salva Peiró discovered an information leak in the Linux kernel's media-
device driver. A local attacker could exploit this flaw to obtain sensitive
information from kernel memory. (CVE-2014-1739)
A bounds check error was discovered in the socket filter subsystem of the
Linux kernel. A local user could exploit this flaw to cause a denial of
service (system crash) via crafted BPF instructions. (CVE-2014-3144)
A remainder calculation error was discovered in the socket filter subsystem
of the Linux kernel. A local user could exploit this flaw to ca
OSV
CVE-2014-3940: The Linux kernel through 3
osv·2014-06-05·CVSS 4.0
CVE-2014-3940 [MEDIUM] CVE-2014-3940: The Linux kernel through 3
The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.c and mm/mempolicy.c.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3940 Kernel: missing check during hugepage migration [fedora-all]
bugzilla·2014-06-05·CVSS 4.0
CVE-2014-3940 [MEDIUM] CVE-2014-3940 Kernel: missing check during hugepage migration [fedora-all]
CVE-2014-3940 Kernel: missing check during hugepage migration [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2014-3940 Kernel: missing check during hugepage migration
bugzilla·2014-06-03·CVSS 4.0
CVE-2014-3940 [MEDIUM] CVE-2014-3940 Kernel: missing check during hugepage migration
CVE-2014-3940 Kernel: missing check during hugepage migration
Linux kernel built with the HugeTLB file system(CONFIG_HUGETLBFS
+ CONFIG_HUGETLB_PAGE) along with Non Uniform Memory Access(CONFIG_NUMA)
support is vulnerable to possible race conditions. It could occur when kernel
attempts to perform hugepage migration.
Upstream fix:
-> https://lkml.org/lkml/2014/3/18/784 (only part 1 of the 2 patches)
Ie: mm: add !pte_present() check on existing hugetlb_entry callbacks
Reference:
-> http://seclists.org/oss-sec/2014/q2/399
Discussion:
Statement:
This issue did not affect the version of the kernel package as shipped with
Red Hat Enterprise Linux 5.
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1105042]
---
kernel-3.14.6-200.fc20 has been pushed to the Fedo
http://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1272.htmlhttp://secunia.com/advisories/59011http://secunia.com/advisories/61310http://www.openwall.com/lists/oss-security/2014/06/02/5http://www.securityfocus.com/bid/67786https://bugzilla.redhat.com/show_bug.cgi?id=1104097https://lkml.org/lkml/2014/3/18/784https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15685.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1272.htmlhttp://secunia.com/advisories/59011http://secunia.com/advisories/61310http://www.openwall.com/lists/oss-security/2014/06/02/5http://www.securityfocus.com/bid/67786https://bugzilla.redhat.com/show_bug.cgi?id=1104097https://lkml.org/lkml/2014/3/18/784https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15685.html
2014-06-05
Published