CVE-2014-4171
published 2014-06-23CVE-2014-4171: mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local…
PriorityP416medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.44%
36.2th percentile
mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE madvise call or (2) an FALLOC_FL_PUNCH_HOLE fallocate call.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 3.14.15-1 (bookworm) | linux 3.14.15-1 (bookworm) |
| linux | linux_kernel | <= 3.15.1 | — |
| linux | linux_kernel | >= 0 < 3.14.15-1 | 3.14.15-1 |
| linux | linux_kernel | >= 0 < 3.14.15-1 | 3.14.15-1 |
| linux | linux_kernel | >= 0 < 3.14.15-1 | 3.14.15-1 |
| linux | linux_kernel | >= 0 < 3.14.15-1 | 3.14.15-1 |
| linux | linux_kernel | >= 0 < 3.13.0-35.62 | 3.13.0-35.62 |
CVSS provenance
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 3.3
CVE-2014-3917 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An flaw was discovered in the Linux kernel's audit subsystem when auditing
certain syscalls. A local attacker could exploit this flaw to obtain
potentially sensitive single-bit values from kernel memory or cause a
denial of service (OOPS). (CVE-2014-3917)
An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)
Sasha Levin reported an issue with the Linux kernel's shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 3.3
CVE-2014-3917 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An flaw was discovered in the Linux kernel's audit subsystem when auditing
certain syscalls. A local attacker could exploit this flaw to obtain
potentially sensitive single-bit values from kernel memory or cause a
denial of service (OOPS). (CVE-2014-3917)
An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)
Sasha Levin reported an issue with the Linux kernel's shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause a denial
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel mem
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-201
Red Hat
Kernel: mm/shmem: denial of service
vendor_redhat·2014-06-17·CVSS 4.7
CVE-2014-4171 [MEDIUM] Kernel: mm/shmem: denial of service
Kernel: mm/shmem: denial of service
mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE madvise call or (2) an FALLOC_FL_PUNCH_HOLE fallocate call.
A race condition flaw was found in the way the Linux kernel's mmap(2), madvise(2), and fallocate(2) system calls interacted with each other while operating on virtual memory file system files. A local user could use this flaw to cause a denial of service.
Statement: This issue does not affect the versions of Linux kernel as shipped with Red
Debian
CVE-2014-4171: linux - mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the in...
vendor_debian·2014·CVSS 4.7
CVE-2014-4171 [MEDIUM] CVE-2014-4171: linux - mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the in...
mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE madvise call or (2) an FALLOC_FL_PUNCH_HOLE fallocate call.
Scope: local
bookworm: resolved (fixed in 3.14.15-1)
bullseye: resolved (fixed in 3.14.15-1)
forky: resolved (fixed in 3.14.15-1)
sid: resolved (fixed in 3.14.15-1)
trixie: resolved (fixed in 3.14.15-1)
GHSA
GHSA-p5vf-58qw-qq73: mm/shmem
ghsa_unreviewed·2022-05-14
CVE-2014-4171 [MEDIUM] GHSA-p5vf-58qw-qq73: mm/shmem
mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE madvise call or (2) an FALLOC_FL_PUNCH_HOLE fallocate call.
OSV
linux vulnerabilities
osv·2014-09-02·CVSS 5.5
CVE-2014-0155 [MEDIUM] linux vulnerabilities
linux vulnerabilities
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-2014-0206)
A flaw was discovered in the Linux kernel's implementation of use
Kernel
shmem: fix faulting into a hole, not taking i_mutex
kernel_security·2014-07-23·CVSS 4.7
CVE-2014-4171 [MEDIUM] shmem: fix faulting into a hole, not taking i_mutex
shmem: fix faulting into a hole, not taking i_mutex
Commit f00cdc6df7d7 ("shmem: fix faulting into a hole while it's
punched") was buggy: Sasha sent a lockdep report to remind us that
grabbing i_mutex in the fault path is a no-no (write syscall may already
hold i_mutex while faulting user buffer).
We tried a completely different approach (see following patch) but that
proved inadequate: good enough for a rational workload, but not good
enough against trinity - which forks off so many mappings of the object
that contention on i_mmap_mutex while hole-puncher holds i_mutex builds
into serious starvation when concurrent faults force the puncher to fall
back to single-page unmap_mapping_range() searches of the i_mmap tree.
So return to the original umbrella approach, but keep away from i_mut
OSV
CVE-2014-4171: mm/shmem
osv·2014-06-23·CVSS 4.7
CVE-2014-4171 [MEDIUM] CVE-2014-4171: mm/shmem
mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE madvise call or (2) an FALLOC_FL_PUNCH_HOLE fallocate call.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-4171 Kernel: mm/shmem: denial of service [fedora-all]
bugzilla·2014-07-10·CVSS 4.7
CVE-2014-4171 [MEDIUM] CVE-2014-4171 Kernel: mm/shmem: denial of service [fedora-all]
CVE-2014-4171 Kernel: mm/shmem: denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When creating a Bodhi update request, use the bodhi submission link noted
in the next comment(s). This will include the bug IDs of this tracking
bug as well as the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
Bodhi notes field when available.
NOTE: this issue affects multiple supported versi
Bugzilla
CVE-2014-4171 Kernel: mm/shmem: denial of service
bugzilla·2014-06-19·CVSS 4.7
CVE-2014-4171 [MEDIUM] CVE-2014-4171 Kernel: mm/shmem: denial of service
CVE-2014-4171 Kernel: mm/shmem: denial of service
Linux kernel built with the shared memory support is vulnerable to a denial of service flaw caused by a race condition in mmap access to a hole, while it is punched from shmem and madvise(2) & fallocate(2) calls. In that mmap access could prevent the other calls from completing.
A user/process could use this flaw to cause a DoS.
Upstream fixes:
-> https://git.kernel.org/linus/f00cdc6df7d7cfcabb5b740911e6788cb0802bdb
-> https://git.kernel.org/linus/8e205f779d1443a94b5ae81aa359cb535dd3021e
-> https://git.kernel.org/linus/b1a366500bd537b50c3aad26dc7df083ec03a448
Reference:
-> http://www.openwall.com/lists/oss-security/2014/06/18/11
Discussion:
Statement:
This issue does not affect the versions of Linux kernel as shipped with Red Hat Ent
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlhttp://marc.info/?l=linux-mm-commits&m=140303745420549&w=2http://ozlabs.org/~akpm/mmots/broken-out/shmem-fix-faulting-into-a-hole-while-its-punched.patchhttp://rhn.redhat.com/errata/RHSA-2014-1318.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0102.htmlhttp://secunia.com/advisories/59777http://secunia.com/advisories/60564http://www.openwall.com/lists/oss-security/2014/06/18/11http://www.securityfocus.com/bid/68157http://www.securitytracker.com/id/1030450http://www.ubuntu.com/usn/USN-2334-1http://www.ubuntu.com/usn/USN-2335-1https://bugzilla.redhat.com/show_bug.cgi?id=1111180http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlhttp://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlhttp://marc.info/?l=linux-mm-commits&m=140303745420549&w=2http://ozlabs.org/~akpm/mmots/broken-out/shmem-fix-faulting-into-a-hole-while-its-punched.patchhttp://rhn.redhat.com/errata/RHSA-2014-1318.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0102.htmlhttp://secunia.com/advisories/59777http://secunia.com/advisories/60564http://www.openwall.com/lists/oss-security/2014/06/18/11http://www.securityfocus.com/bid/68157http://www.securitytracker.com/id/1030450http://www.ubuntu.com/usn/USN-2334-1http://www.ubuntu.com/usn/USN-2335-1https://bugzilla.redhat.com/show_bug.cgi?id=1111180
2014-06-23
Published