CVE-2014-4027Sensitive Information Exposure in Kernel

Severity
2.3LOWNVD
EPSS
0.1%
top 74.32%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 23
Latest updateMay 13

Description

The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator.

CVSS vector

AV:A/AC:M/C:P/I:N/A:NExploitability: 4.4 | Impact: 2.9

Affected Packages25 packages

NVDlinux/linux_kernel< 3.14
Debianlinux/linux_kernel< 3.14.2-1+3
NVDf5/big-ip_access_policy_manager11.1.011.6.0+1
NVDf5/big-ip_local_traffic_manager11.1.011.6.0+1

Also affects: Ubuntu Linux 12.04, Enterprise Linux 6.0

Patches

🔴Vulnerability Details

3
GHSA
GHSA-j649-2854-8rqg: The rd_build_device_space function in drivers/target/target_core_rd2022-05-13
CVEList
CVE-2014-4027: The rd_build_device_space function in drivers/target/target_core_rd2014-06-23
OSV
CVE-2014-4027: The rd_build_device_space function in drivers/target/target_core_rd2014-06-23

📋Vendor Advisories

7
Ubuntu
Linux kernel (OMAP4) vulnerabilities2014-09-02
Ubuntu
Linux kernel vulnerabilities2014-09-02
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2014-09-02
Ubuntu
Linux kernel vulnerabilities2014-09-02
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities2014-07-17

💬Community

1
Bugzilla
CVE-2014-4027 Kernel: target/rd: imformation leakage2014-06-12
CVE-2014-4027 — Sensitive Information Exposure | cvebase