CVE-2014-7975
published 2014-10-13CVE-2014-7975: The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the…
PriorityP421medium5.5CVSS 3.1
AVLACLPRLUINSUCNINAH
EPSS
0.46%
37.7th percentile
The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 3.16.7-1 (bookworm) | linux 3.16.7-1 (bookworm) |
| linux | linux_kernel | <= 3.17 | — |
| linux | linux_kernel | >= 0 < 3.16.7-1 | 3.16.7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-1 | 3.16.7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-1 | 3.16.7-1 |
| linux | linux_kernel | >= 0 < 3.16.7-1 | 3.16.7-1 |
| linux | linux_kernel | >= 0 < 3.13.0-40.69 | 3.13.0-40.69 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_ubuntu7.3HIGH
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-11-25·CVSS 7.3
CVE-2014-4608 [HIGH] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Don Bailey discovered a flaw in the LZO decompress algorithm used by the
Linux kernel. An attacker could exploit this flaw to cause a denial of
service (memory corruption or OOPS). (CVE-2014-4608)
Andy Lutomirski discovered that the Linux kernel was not checking the
CAP_SYS_ADMIN when remounting filesystems to read-only. A local user could
exploit this flaw to cause a denial of service (loss of writability).
(CVE-2014-7975)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all th
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-11-25·CVSS 5.5
CVE-2014-3690 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in how the Linux kernel's KVM (Kernel Virtual
Machine) subsystem handles the CR4 control register at VM entry on Intel
processors. A local host OS user can exploit this to cause a denial of
service (kill arbitrary processes, or system disruption) by leveraging
/dev/kvm access. (CVE-2014-3690)
Don Bailey discovered a flaw in the LZO decompress algorithm used by the
Linux kernel. An attacker could exploit this flaw to cause a denial of
service (memory corruption or OOPS). (CVE-2014-4608)
Andy Lutomirski discovered that the Linux kernel was not checking the
CAP_SYS_ADMIN when remounting filesystems to read-only. A local user could
exploit this flaw to cause a denial of serv
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-11-25·CVSS 5.5
CVE-2014-3690 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in how the Linux kernel's KVM (Kernel Virtual
Machine) subsystem handles the CR4 control register at VM entry on Intel
processors. A local host OS user can exploit this to cause a denial of
service (kill arbitrary processes, or system disruption) by leveraging
/dev/kvm access. (CVE-2014-3690)
Don Bailey discovered a flaw in the LZO decompress algorithm used by the
Linux kernel. An attacker could exploit this flaw to cause a denial of
service (memory corruption or OOPS). (CVE-2014-4608)
Andy Lutomirski discovered a flaw in how the Linux kernel handles
pivot_root when used with a chroot directory. A local user could exploit
this flaw to cause a denial of servi
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-11-25·CVSS 5.5
CVE-2014-3610 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
A flaw was discovered with invept instruction support when using nested EPT
in the KVM (Kernel Virtual Machine). An unprivileged guest user coul
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-11-25·CVSS 5.5
CVE-2014-3610 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Nadav Amit reported that the KVM (Kernel Virtual Machine) mishandles
noncanonical addresses when emulating instructions that change the rip
(Instruction Pointer). A guest user with access to I/O or the MMIO can use
this flaw to cause a denial of service (system crash) of the guest.
(CVE-2014-3647)
A flaw was discovered with the handling of the invept instruction in the
KVM (Kernel Virtual Machine) subsystem of the Linux kernel. An unprivileged
guest user could exploit this flaw to cause a denial of service (system
crash) on the guest. (CVE-2014-3646)
A flaw was discovered with invept instruction support when using nested EPT
in the KVM (Kernel Virtual Machine). An unprivileged guest u
Ubuntu
Linux kernel vulnerability
vendor_ubuntu·2014-11-25·CVSS 7.3
CVE-2014-4608 [HIGH] Linux kernel vulnerability
Title: Linux kernel vulnerability
Summary: The system could be made to deny write access to files.
Don Bailey discovered a flaw in the LZO decompress algorithm used by the
Linux kernel. An attacker could exploit this flaw to cause a denial of
service (memory corruption or OOPS). (CVE-2014-4608)
Andy Lutomirski discovered that the Linux kernel was not checking the
CAP_SYS_ADMIN when remounting filesystems to read-only. A local user could
exploit this flaw to cause a denial of service (loss of writability).
(CVE-2014-7975)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all thir
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-11-25·CVSS 5.5
CVE-2014-3690 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in how the Linux kernel's KVM (Kernel Virtual
Machine) subsystem handles the CR4 control register at VM entry on Intel
processors. A local host OS user can exploit this to cause a denial of
service (kill arbitrary processes, or system disruption) by leveraging
/dev/kvm access. (CVE-2014-3690)
Don Bailey discovered a flaw in the LZO decompress algorithm used by the
Linux kernel. An attacker could exploit this flaw to cause a denial of
service (memory corruption or OOPS). (CVE-2014-4608)
Andy Lutomirski discovered a flaw in how the Linux kernel handles
pivot_root when used with a chroot directory. A local user could exploit
this flaw to cause a denial of service (mount-tre
Red Hat
Kernel: fs: umount denial of service
vendor_redhat·2014-10-08·CVSS 5.5
CVE-2014-7975 [MEDIUM] Kernel: fs: umount denial of service
Kernel: fs: umount denial of service
The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: realtime-krenel (Red Hat Enterprise MRG 2) - Not affected
Debian
CVE-2014-7975: linux - The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does n...
vendor_debian·2014·CVSS 5.5
CVE-2014-7975 [MEDIUM] CVE-2014-7975: linux - The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does n...
The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.
Scope: local
bookworm: resolved (fixed in 3.16.7-1)
bullseye: resolved (fixed in 3.16.7-1)
forky: resolved (fixed in 3.16.7-1)
sid: resolved (fixed in 3.16.7-1)
trixie: resolved (fixed in 3.16.7-1)
GHSA
GHSA-jvc4-gpm6-jw84: The do_umount function in fs/namespace
ghsa_unreviewed·2022-05-13
CVE-2014-7975 [MEDIUM] GHSA-jvc4-gpm6-jw84: The do_umount function in fs/namespace
The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.
OSV
linux vulnerabilities
osv·2014-11-25·CVSS 5.5
CVE-2014-3690 [MEDIUM] linux vulnerabilities
linux vulnerabilities
A flaw was discovered in how the Linux kernel's KVM (Kernel Virtual
Machine) subsystem handles the CR4 control register at VM entry on Intel
processors. A local host OS user can exploit this to cause a denial of
service (kill arbitrary processes, or system disruption) by leveraging
/dev/kvm access. (CVE-2014-3690)
Don Bailey discovered a flaw in the LZO decompress algorithm used by the
Linux kernel. An attacker could exploit this flaw to cause a denial of
service (memory corruption or OOPS). (CVE-2014-4608)
Andy Lutomirski discovered a flaw in how the Linux kernel handles
pivot_root when used with a chroot directory. A local user could exploit
this flaw to cause a denial of service (mount-tree loop). (CVE-2014-7970)
Andy Lutomirski discovered that the Linux kernel
Kernel
Merge branch 'CVE-2014-7975' of git://git.kernel.org/pub/scm/linux/kernel/git/luto/linux
kernel_security·2014-10-14·CVSS 5.5
CVE-2014-7975 [MEDIUM] Merge branch 'CVE-2014-7975' of git://git.kernel.org/pub/scm/linux/kernel/git/luto/linux
Merge branch 'CVE-2014-7975' of git://git.kernel.org/pub/scm/linux/kernel/git/luto/linux
Pull do_umount fix from Andy Lutomirski:
"This fix really ought to be safe. Inside a mountns owned by a
non-root user namespace, the namespace root almost always has
MNT_LOCKED set (if it doesn't, then there's a bug, because rootfs
could be exposed). In that case, calling umount on "/" will return
-EINVAL with or without this patch.
Outside a userns, this patch will have no effect. may_mount, required
by umount, already checks
ns_capable(current->nsproxy->mnt_ns->user_ns, CAP_SYS_ADMIN)
so an additional capable(CAP_SYS_ADMIN) check will have no effect.
That leaves anything that calls umount on "/" in a non-root userns
while chrooted. This is the case that is currently broken (it
remounts ro, which s
OSV
CVE-2014-7975: The do_umount function in fs/namespace
osv·2014-10-13·CVSS 5.5
CVE-2014-7975 [MEDIUM] CVE-2014-7975: The do_umount function in fs/namespace
The do_umount function in fs/namespace.c in the Linux kernel through 3.17 does not require the CAP_SYS_ADMIN capability for do_remount_sb calls that change the root filesystem to read-only, which allows local users to cause a denial of service (loss of writability) by making certain unshare system calls, clearing the / MNT_LOCKED flag, and making an MNT_FORCE umount system call.
Kernel
fs: Add a missing permission check to do_umount
kernel_security·2014-10-08·CVSS 5.5
CVE-2014-7975 [MEDIUM] fs: Add a missing permission check to do_umount
fs: Add a missing permission check to do_umount
Accessing do_remount_sb should require global CAP_SYS_ADMIN, but
only one of the two call sites was appropriately protected.
Fixes CVE-2014-7975.
Signed-off-by: Andy Lutomirski
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7975 Kernel: fs: umount denial of service [fedora-all]
bugzilla·2014-10-13·CVSS 5.5
CVE-2014-7975 [MEDIUM] CVE-2014-7975 Kernel: fs: umount denial of service [fedora-all]
CVE-2014-7975 Kernel: fs: umount denial of service [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While
Bugzilla
CVE-2014-7975 Kernel: fs: umount denial of service
bugzilla·2014-10-09·CVSS 5.5
CVE-2014-7975 [MEDIUM] CVE-2014-7975 Kernel: fs: umount denial of service
CVE-2014-7975 Kernel: fs: umount denial of service
Linux kernel file system implementation is vulnerable to a DoS flaw. It could occur by doing umount(2) call from within user name spaces.
An unprivileged user/process could use this flaw to render the system unusable by making file system inaccessible.
Upstream fix:
-> http://thread.gmane.org/gmane.linux.kernel.stable/109312
Reference:
-> http://seclists.org/oss-sec/2014/q4/229
Discussion:
Statement:
This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2.
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1152025]
---
Upstream commit:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0ef3a56b1c466
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0ef3a56b1c466629cd0bf482b09c7b0e5a085bb5http://secunia.com/advisories/60174http://secunia.com/advisories/61145http://secunia.com/advisories/62633http://secunia.com/advisories/62634http://thread.gmane.org/gmane.linux.kernel.stable/109312http://www.openwall.com/lists/oss-security/2014/10/08/22http://www.securityfocus.com/bid/70314http://www.securitytracker.com/id/1031180http://www.ubuntu.com/usn/USN-2415-1http://www.ubuntu.com/usn/USN-2416-1http://www.ubuntu.com/usn/USN-2417-1http://www.ubuntu.com/usn/USN-2418-1http://www.ubuntu.com/usn/USN-2419-1http://www.ubuntu.com/usn/USN-2420-1http://www.ubuntu.com/usn/USN-2421-1https://access.redhat.com/errata/RHSA-2017:1842https://access.redhat.com/errata/RHSA-2017:2077https://bugzilla.redhat.com/show_bug.cgi?id=1151108https://exchange.xforce.ibmcloud.com/vulnerabilities/96994http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=0ef3a56b1c466629cd0bf482b09c7b0e5a085bb5http://secunia.com/advisories/60174http://secunia.com/advisories/61145http://secunia.com/advisories/62633http://secunia.com/advisories/62634http://thread.gmane.org/gmane.linux.kernel.stable/109312http://www.openwall.com/lists/oss-security/2014/10/08/22http://www.securityfocus.com/bid/70314http://www.securitytracker.com/id/1031180http://www.ubuntu.com/usn/USN-2415-1http://www.ubuntu.com/usn/USN-2416-1http://www.ubuntu.com/usn/USN-2417-1http://www.ubuntu.com/usn/USN-2418-1http://www.ubuntu.com/usn/USN-2419-1http://www.ubuntu.com/usn/USN-2420-1http://www.ubuntu.com/usn/USN-2421-1https://access.redhat.com/errata/RHSA-2017:1842https://access.redhat.com/errata/RHSA-2017:2077https://bugzilla.redhat.com/show_bug.cgi?id=1151108https://exchange.xforce.ibmcloud.com/vulnerabilities/96994
2014-10-13
Published