CVE-2014-7283
published 2014-10-13CVE-2014-7283: The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash…
PriorityP416medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.55%
42.1th percentile
The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.2-1 (bookworm) | linux 3.16.2-1 (bookworm) |
| linux | linux_kernel | < 3.14.2 | 3.14.2 |
| linux | linux_kernel | >= 0 < 3.16.2-1 | 3.16.2-1 |
| linux | linux_kernel | >= 0 < 3.16.2-1 | 3.16.2-1 |
| linux | linux_kernel | >= 0 < 3.16.2-1 | 3.16.2-1 |
| linux | linux_kernel | >= 0 < 3.16.2-1 | 3.16.2-1 |
| linux | linux_kernel | >= 0 < 3.13.0-27.50 | 3.13.0-27.50 |
| redhat | mrg_realtime | — | — |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_ubuntu5.5MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: xfs: directory hash ordering denial of service
vendor_redhat·2014-10-02·CVSS 4.9
CVE-2014-7283 [MEDIUM] kernel: xfs: directory hash ordering denial of service
kernel: xfs: directory hash ordering denial of service
The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations.
A denial of service flaw was found in the way the Linux kernel's XFS file system implementation ordered directory hashes under certain conditions. A local attacker could use this flaw to corrupt the file system by creating directories with colliding hash values, potentially resulting in a system crash.
Statement: This issue does not affect the Linux kernel packages as shipped with Red
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-06-27·CVSS 5.5
CVE-2014-0077 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's pseudo tty (pty) device. An
unprivileged user could exploit this flaw to cause a denial of service
(system crash) or potentially gain administrator privileges.
(CVE-2014-0196)
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-06-05·CVSS 5.5
CVE-2014-0155 [MEDIUM] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Pinkie Pie discovered a flaw in the Linux kernel's futex subsystem. An
unprivileged local user could exploit this flaw to cause a denial of
service (system crash) or gain administrative privileges. (CVE-2014-3153)
A flaw was discovered in the Linux kernel virtual machine's (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)
An information leak was discovered in the netfilter subsystem of the Linux
kernel. An attacker could exploit this flaw to obtain sensitive information
from kernel memory. (CVE-2014-2568)
Sasha Levin reported a bug in the Linux kernel's virtual memory management
subs
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-05-27·CVSS 5.5
CVE-2014-0077 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in the handling of ioctl commands by the
floppy disk driver in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges if the floppy disk
module is loaded. (CVE-2014-1737)
A flaw was discovered in the handling of network packets when mergeable
buffers are disabled for virtual machines in the Linux kernel. Guest OS
users may exploit this flaw to cause a denial of service (host OS crash) or
possibly ga
Debian
CVE-2014-7283: linux - The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementat...
vendor_debian·2014·CVSS 4.9
CVE-2014-7283 [MEDIUM] CVE-2014-7283: linux - The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementat...
The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations.
Scope: local
bookworm: resolved (fixed in 3.16.2-1)
bullseye: resolved (fixed in 3.16.2-1)
forky: resolved (fixed in 3.16.2-1)
sid: resolved (fixed in 3.16.2-1)
trixie: resolved (fixed in 3.16.2-1)
GHSA
GHSA-r29j-j5r6-jhjm: The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree
ghsa_unreviewed·2022-05-13
CVE-2014-7283 [MEDIUM] GHSA-r29j-j5r6-jhjm: The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree
The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations.
OSV
CVE-2014-7283: The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree
osv·2014-10-13·CVSS 4.9
CVE-2014-7283 [MEDIUM] CVE-2014-7283: The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree
The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations.
OSV
linux vulnerabilities
osv·2014-05-27·CVSS 5.5
CVE-2014-1738 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in the handling of ioctl commands by the
floppy disk driver in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges if the floppy disk
module is loaded. (CVE-2014-1737)
A flaw was discovered in the handling of network packets when mergeable
buffers are disabled for virtual machines in the Linux kernel. Guest OS
users may exploit this flaw to cause a denial of service (host OS crash) or
possibly gain privilege on the host OS. (CVE-2014-0077)
Török Edwin discovered a fla
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c88547a8119e3b581318ab65e9b72f27f23e641dhttp://marc.info/?l=linux-xfs&m=139590613002926&w=2http://rhn.redhat.com/errata/RHSA-2014-1943.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.2http://www.openwall.com/lists/oss-security/2014/10/01/29http://www.securityfocus.com/bid/70261https://bugzilla.redhat.com/show_bug.cgi?id=1148777https://github.com/torvalds/linux/commit/c88547a8119e3b581318ab65e9b72f27f23e641dhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c88547a8119e3b581318ab65e9b72f27f23e641dhttp://marc.info/?l=linux-xfs&m=139590613002926&w=2http://rhn.redhat.com/errata/RHSA-2014-1943.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.2http://www.openwall.com/lists/oss-security/2014/10/01/29http://www.securityfocus.com/bid/70261https://bugzilla.redhat.com/show_bug.cgi?id=1148777https://github.com/torvalds/linux/commit/c88547a8119e3b581318ab65e9b72f27f23e641d
2014-10-13
Published