cbcvebase.
CVE-2014-4171
published 2014-06-23

CVE-2014-4171: mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local…

PriorityP416medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.44%
36.2th percentile
mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE madvise call or (2) an FALLOC_FL_PUNCH_HOLE fallocate call.

Affected

8 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianlinux< linux 3.14.15-1 (bookworm)linux 3.14.15-1 (bookworm)
linuxlinux_kernel<= 3.15.1
linuxlinux_kernel>= 0 < 3.14.15-13.14.15-1
linuxlinux_kernel>= 0 < 3.14.15-13.14.15-1
linuxlinux_kernel>= 0 < 3.14.15-13.14.15-1
linuxlinux_kernel>= 0 < 3.14.15-13.14.15-1
linuxlinux_kernel>= 0 < 3.13.0-35.623.13.0-35.62

CVSS provenance

nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.