CVE-2014-7145
published 2014-09-28CVE-2014-7145: The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference…
PriorityP433high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
3.72%
88.6th percentile
The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other impact by deleting the IPC$ share during resolution of DFS referrals.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 3.16.3-1 (bookworm) | linux 3.16.3-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.16.3-1 | 3.16.3-1 |
| linux | linux_kernel | >= 0 < 3.16.3-1 | 3.16.3-1 |
| linux | linux_kernel | >= 0 < 3.16.3-1 | 3.16.3-1 |
| linux | linux_kernel | >= 0 < 3.16.3-1 | 3.16.3-1 |
| linux | linux_kernel | >= 0 < 3.13.0-39.66 | 3.13.0-39.66 |
| linux | linux_kernel | >= 3.11 < 3.12.29 | 3.12.29 |
| linux | linux_kernel | >= 3.13 < 3.14.19 | 3.14.19 |
| linux | linux_kernel | >= 3.15 < 3.16.3 | 3.16.3 |
| linux | linux_kernel | >= 3.6 < 3.10.55 | 3.10.55 |
| redhat | enterprise_linux_desktop | — | — |
| redhat | enterprise_linux_hpc_node | — | — |
| redhat | enterprise_linux_server | — | — |
| redhat | enterprise_linux_workstation | — | — |
CVSS provenance
nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pcv5-8q8x-qqfx: The SMB2_tcon function in fs/cifs/smb2pdu
ghsa_unreviewed·2022-05-17
CVE-2014-7145 [HIGH] GHSA-pcv5-8q8x-qqfx: The SMB2_tcon function in fs/cifs/smb2pdu
The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other impact by deleting the IPC$ share during resolution of DFS referrals.
OSV
linux vulnerabilities
osv·2014-10-30·CVSS 6.9
CVE-2014-3647 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
Lars Bull reported a race condition in the PIT (programmable interrupt
timer) emulation in the KVM (Kernel Virtual Machine) subsystem of the Linux
kernel. A local guest user with access to PIT i/o ports could exploit t
OSV
CVE-2014-7145: The SMB2_tcon function in fs/cifs/smb2pdu
osv·2014-09-28·CVSS 7.8
CVE-2014-7145 [HIGH] CVE-2014-7145: The SMB2_tcon function in fs/cifs/smb2pdu
The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other impact by deleting the IPC$ share during resolution of DFS referrals.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-10-30·CVSS 6.9
CVE-2014-3182 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
Lars Bull reported a race condition in the PIT (programmable interrupt
timer) emulation in the KVM (Kernel Virtual Machine) subsystem of the Lin
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-10-30·CVSS 6.9
CVE-2014-3182 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
Lars Bull reported a race condition in the PIT (programmable interrupt
timer) emulation in the KVM (Kernel Virtual Machine) subsyst
Red Hat
Kernel: cifs: NULL pointer dereference in SMB2_tcon
vendor_redhat·2014-08-17·CVSS 7.8
CVE-2014-7145 [HIGH] CWE-476 Kernel: cifs: NULL pointer dereference in SMB2_tcon
Kernel: cifs: NULL pointer dereference in SMB2_tcon
The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other impact by deleting the IPC$ share during resolution of DFS referrals.
A NULL pointer dereference flaw was found in the way the Linux kernel's Common Internet File System (CIFS) implementation handled mounting of file system shares. A remote attacker could use this flaw to crash a client system that would mount a file system share from a malicious server.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG 2.
This issue affects
Debian
CVE-2014-7145: linux - The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 al...
vendor_debian·2014·CVSS 7.8
CVE-2014-7145 [HIGH] CVE-2014-7145: linux - The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 al...
The SMB2_tcon function in fs/cifs/smb2pdu.c in the Linux kernel before 3.16.3 allows remote CIFS servers to cause a denial of service (NULL pointer dereference and client system crash) or possibly have unspecified other impact by deleting the IPC$ share during resolution of DFS referrals.
Scope: local
bookworm: resolved (fixed in 3.16.3-1)
bullseye: resolved (fixed in 3.16.3-1)
forky: resolved (fixed in 3.16.3-1)
sid: resolved (fixed in 3.16.3-1)
trixie: resolved (fixed in 3.16.3-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7145 Kernel: cifs: NULL pointer dereference in SMB2_tcon
bugzilla·2014-09-29·CVSS 7.8
CVE-2014-7145 [HIGH] CVE-2014-7145 Kernel: cifs: NULL pointer dereference in SMB2_tcon
CVE-2014-7145 Kernel: cifs: NULL pointer dereference in SMB2_tcon
Linux kernel built with the Network Filesystem CIFS support(CONFIG_CIFS) along
with the support for SMB2 and SMB3 network file systems(CONFIG_CIFS_SMB2) is
vulnerable to a NULL pointer dereference flaw. It could occur while mounting
the remote file system share.
A remote attacker could use this flaw to crash the client systems resulting in DoS.
Upstream fix:
-> https://git.kernel.org/linus/18f39e7be0121317550d03e267e3ebd4dbfbb3ce
Discussion:
Statement:
This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6, and Red Hat Enterprise MRG 2.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 7. Future kernel updates for Red Hat Enterp
Bugzilla
CVE-2014-7145 Kernel: cifs: NULL pointer dereference in SMB2_tcon [fedora-all]
bugzilla·2014-09-29·CVSS 7.8
CVE-2014-7145 [HIGH] CVE-2014-7145 Kernel: cifs: NULL pointer dereference in SMB2_tcon [fedora-all]
CVE-2014-7145 Kernel: cifs: NULL pointer dereference in SMB2_tcon [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=18f39e7be0121317550d03e267e3ebd4dbfbb3cehttp://rhn.redhat.com/errata/RHSA-2015-0102.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.16.3http://www.openwall.com/lists/oss-security/2014/09/22/4http://www.securityfocus.com/bid/69867http://www.ubuntu.com/usn/USN-2394-1https://github.com/torvalds/linux/commit/18f39e7be0121317550d03e267e3ebd4dbfbb3cehttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=18f39e7be0121317550d03e267e3ebd4dbfbb3cehttp://rhn.redhat.com/errata/RHSA-2015-0102.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.16.3http://www.openwall.com/lists/oss-security/2014/09/22/4http://www.securityfocus.com/bid/69867http://www.ubuntu.com/usn/USN-2394-1https://github.com/torvalds/linux/commit/18f39e7be0121317550d03e267e3ebd4dbfbb3ce
2014-09-28
Published