CVE-2014-5045
published 2014-08-01CVE-2014-5045: The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to use the…
PriorityP420medium6.2CVSS 2.0
AVLACHAuNCCICAC
EPSS
0.49%
39.2th percentile
The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to use the umount system call in conjunction with a symlink, which allows local users to cause a denial of service (memory consumption or use-after-free) or possibly have unspecified other impact via the umount program.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.14.15-1 (bookworm) | linux 3.14.15-1 (bookworm) |
| linux | linux_kernel | < 3.15.8 | 3.15.8 |
| linux | linux_kernel | >= 0 < 3.14.15-1 | 3.14.15-1 |
| linux | linux_kernel | >= 0 < 3.14.15-1 | 3.14.15-1 |
| linux | linux_kernel | >= 0 < 3.14.15-1 | 3.14.15-1 |
| linux | linux_kernel | >= 0 < 3.14.15-1 | 3.14.15-1 |
| linux | linux_kernel | >= 0 < 3.13.0-35.62 | 3.13.0-35.62 |
| redhat | enterprise_linux_eus | — | — |
| redhat | enterprise_linux_server_aus | — | — |
| redhat | enterprise_linux_server_tus | — | — |
CVSS provenance
nvdv2.06.2MEDIUMAV:L/AC:H/Au:N/C:C/I:C/A:C
osv6.2MEDIUM
vendor_debian6.2MEDIUM
vendor_redhat6.2MEDIUM
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9pvv-pv37-92f4: The mountpoint_last function in fs/namei
ghsa_unreviewed·2022-05-13
CVE-2014-5045 [MEDIUM] CWE-59 GHSA-9pvv-pv37-92f4: The mountpoint_last function in fs/namei
The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to use the umount system call in conjunction with a symlink, which allows local users to cause a denial of service (memory consumption or use-after-free) or possibly have unspecified other impact via the umount program.
OSV
linux vulnerabilities
osv·2014-09-02·CVSS 5.5
CVE-2014-0155 [MEDIUM] linux vulnerabilities
linux vulnerabilities
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-2014-0206)
A flaw was discovered in the Linux kernel's implementation of use
OSV
CVE-2014-5045: The mountpoint_last function in fs/namei
osv·2014-08-01·CVSS 6.2
CVE-2014-5045 [MEDIUM] CVE-2014-5045: The mountpoint_last function in fs/namei
The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to use the umount system call in conjunction with a symlink, which allows local users to cause a denial of service (memory consumption or use-after-free) or possibly have unspecified other impact via the umount program.
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel mem
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-09-02·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)
An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-201
Red Hat
kernel: vfs: refcount issues during unmount on symlink
vendor_redhat·2014-07-20·CVSS 6.2
CVE-2014-5045 [MEDIUM] kernel: vfs: refcount issues during unmount on symlink
kernel: vfs: refcount issues during unmount on symlink
The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to use the umount system call in conjunction with a symlink, which allows local users to cause a denial of service (memory consumption or use-after-free) or possibly have unspecified other impact via the umount program.
A flaw was found in the way the Linux kernel's VFS subsystem handled reference counting when performing unmount operations on symbolic links. A local, unprivileged user could use this flaw to exhaust all available memory on the system or, potentially, trigger a use-after-free error, resulting in a system crash or privilege escalation.
Statement: This issue does not affect L
Debian
CVE-2014-5045: linux - The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 doe...
vendor_debian·2014·CVSS 6.2
CVE-2014-5045 [MEDIUM] CVE-2014-5045: linux - The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 doe...
The mountpoint_last function in fs/namei.c in the Linux kernel before 3.15.8 does not properly maintain a certain reference count during attempts to use the umount system call in conjunction with a symlink, which allows local users to cause a denial of service (memory consumption or use-after-free) or possibly have unspecified other impact via the umount program.
Scope: local
bookworm: resolved (fixed in 3.14.15-1)
bullseye: resolved (fixed in 3.14.15-1)
forky: resolved (fixed in 3.14.15-1)
sid: resolved (fixed in 3.14.15-1)
trixie: resolved (fixed in 3.14.15-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-5045 kernel: vfs: refcount issues during lazy unmount on symlink [fedora-all]
bugzilla·2014-07-23·CVSS 6.2
CVE-2014-5045 [MEDIUM] CVE-2014-5045 kernel: vfs: refcount issues during lazy unmount on symlink [fedora-all]
CVE-2014-5045 kernel: vfs: refcount issues during lazy unmount on symlink [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported ver
Bugzilla
CVE-2014-5045 kernel: vfs: refcount issues during unmount on symlink
bugzilla·2014-07-23·CVSS 6.2
CVE-2014-5045 [MEDIUM] CVE-2014-5045 kernel: vfs: refcount issues during unmount on symlink
CVE-2014-5045 kernel: vfs: refcount issues during unmount on symlink
A flaw was found in the way reference counting was handled in the Linux kernel's
VFS subsystem when unmount on symlink was performed.
On Red Hat Enterprise Linux 6 an unprivileged local user could use this flaw to
cause OOM conditions leading to denial of service or, potentially, trigger
use-after-free error.
On Red Hat Enterprise Linux 7 a privileged local user with CAP_SYS_ADMIN
capability (also in a container) could use this flaw to cause OOM conditions
leading to denial of service or, potentially, trigger use-after-free error.
Acknowledgements:
Red Hat would like to thank Vasily Averin of Parallels for reporting this issue.
Discussion:
Statement:
This issue does not affect Linux kernel packages as shipped with
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=295dc39d941dc2ae53d5c170365af4c9d5c16212http://rhn.redhat.com/errata/RHSA-2015-0062.htmlhttp://secunia.com/advisories/60353http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.15.8http://www.openwall.com/lists/oss-security/2014/07/24/2http://www.securityfocus.com/bid/68862https://bugzilla.redhat.com/show_bug.cgi?id=1122472https://github.com/torvalds/linux/commit/295dc39d941dc2ae53d5c170365af4c9d5c16212http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=295dc39d941dc2ae53d5c170365af4c9d5c16212http://rhn.redhat.com/errata/RHSA-2015-0062.htmlhttp://secunia.com/advisories/60353http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.15.8http://www.openwall.com/lists/oss-security/2014/07/24/2http://www.securityfocus.com/bid/68862https://bugzilla.redhat.com/show_bug.cgi?id=1122472https://github.com/torvalds/linux/commit/295dc39d941dc2ae53d5c170365af4c9d5c16212
2014-08-01
Published