CVE-2014-7283

CWE-39910 documents8 sources
Severity
4.9MEDIUM
EPSS
0.0%
top 87.85%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 13
Latest updateMay 13

Description

The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations.

CVSS vector

AV:L/AC:L/C:N/I:N/A:CExploitability: 3.9 | Impact: 6.9

Affected Packages3 packages

NVDlinux/linux_kernel< 3.14.2
Debianlinux< 3.16.2-1+3

Patches

🔴Vulnerability Details

3
GHSA
GHSA-r29j-j5r6-jhjm: The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree2022-05-13
CVEList
CVE-2014-7283: The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree2014-10-13
OSV
CVE-2014-7283: The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree2014-10-13

📋Vendor Advisories

5
Red Hat
kernel: xfs: directory hash ordering denial of service2014-10-02
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2014-06-27
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities2014-06-05
Ubuntu
Linux kernel vulnerabilities2014-05-27
Debian
CVE-2014-7283: linux - The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementat...2014

💬Community

1
Bugzilla
CVE-2014-7283 kernel: xfs: directory hash ordering denial of service2014-10-02
CVE-2014-7283 (MEDIUM CVSS 4.9) | The xfs_da3_fixhashpath function in | cvebase.io