CVE-2014-8086
published 2014-10-13CVE-2014-8086: Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file…
PriorityP415medium4.7CVSS 3.1
AVLACHPRLUINSUCNINAH
EPSS
0.37%
30.0th percentile
Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT flag.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.7-ckt2-1 (bookworm) | linux 3.16.7-ckt2-1 (bookworm) |
| linux | linux_kernel | <= 3.17 | — |
| linux | linux_kernel | >= 0 < 3.16.7-ckt2-1 | 3.16.7-ckt2-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt2-1 | 3.16.7-ckt2-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt2-1 | 3.16.7-ckt2-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt2-1 | 3.16.7-ckt2-1 |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv3.14.7MEDIUMCVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv7.5HIGH
vendor_ubuntu7.5HIGH
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-9jxp-4r84-xf98: Race condition in the ext4_file_write_iter function in fs/ext4/file
ghsa_unreviewed·2022-05-13
CVE-2014-8086 [MEDIUM] CWE-362 GHSA-9jxp-4r84-xf98: Race condition in the ext4_file_write_iter function in fs/ext4/file
Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT flag.
OSV
linux-lts-utopic regression
osv·2014-12-19·CVSS 7.5
[HIGH] linux-lts-utopic regression
linux-lts-utopic regression
USN-2447-1 fixed vulnerabilities in the Linux kernel. Due to an unrelated
regression TCP Throughput drops to zero for several drivers after upgrading.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private syscall
numbers. A local user could exploit this flaw to cause a den
OSV
linux-lts-utopic vulnerabilities
osv·2014-12-12·CVSS 7.5
CVE-2014-9322 [HIGH] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Andy Lutomirski discovered that the Linux kernel does not properly handle
faults associated with the Stack Segment (SS) register in the x86
architecture. A local attacker could exploit this flaw to gain
administrative privileges. (CVE-2014-9322)
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private syscall
numbers. A local user could exploit this flaw to cause a
OSV
CVE-2014-8086: Race condition in the ext4_file_write_iter function in fs/ext4/file
osv·2014-10-13·CVSS 4.7
CVE-2014-8086 [MEDIUM] CVE-2014-8086: Race condition in the ext4_file_write_iter function in fs/ext4/file
Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT flag.
Ubuntu
Linux kernel regression
vendor_ubuntu·2014-12-19·CVSS 7.5
[HIGH] Linux kernel regression
Title: Linux kernel regression
Summary: USN-2448-1 introduced a regression in the Linux kernel.
USN-2448-1 fixed vulnerabilities in the Linux kernel. Due to an unrelated
regression TCP Throughput drops to zero for several drivers after upgrading.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private
Ubuntu
Linux kernel (Utopic HWE) regression
vendor_ubuntu·2014-12-19·CVSS 7.5
[HIGH] Linux kernel (Utopic HWE) regression
Title: Linux kernel (Utopic HWE) regression
Summary: USN-2447-1 introduced a regression in the Linux kernel.
USN-2447-1 fixed vulnerabilities in the Linux kernel. Due to an unrelated
regression TCP Throughput drops to zero for several drivers after upgrading.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly h
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.5
CVE-2014-3673 [HIGH] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered that the Linux kernel does not properly handle
faults associated with the Stack Segment (SS) register in the x86
architecture. A local attacker could exploit this flaw to gain
administrative privileges. (CVE-2014-9322)
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly han
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.5
CVE-2014-3673 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered that the Linux kernel does not properly handle
faults associated with the Stack Segment (SS) register in the x86
architecture. A local attacker could exploit this flaw to gain
administrative privileges. (CVE-2014-9322)
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private s
Red Hat
Kernel: fs: ext4 race condition
vendor_redhat·2014-10-09·CVSS 4.7
CVE-2014-8086 [MEDIUM] Kernel: fs: ext4 race condition
Kernel: fs: ext4 race condition
Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT flag.
A race condition flaw was found in the Linux kernel's ext4 file system implementation that allowed a local, unprivileged user to crash the system by simultaneously writing to a file and toggling the O_DIRECT flag using fcntl(F_SETFL) on that file.
Statement: This issue does not affect the versions of Linux kernel as shipped with
Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6.
This issue affects the version of the kernel package as shipped with
Red Hat Enterprise Linux 7 and Red Hat Ente
Debian
CVE-2014-8086: linux - Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Lin...
vendor_debian·2014·CVSS 4.7
CVE-2014-8086 [MEDIUM] CVE-2014-8086: linux - Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Lin...
Race condition in the ext4_file_write_iter function in fs/ext4/file.c in the Linux kernel through 3.17 allows local users to cause a denial of service (file unavailability) via a combination of a write action and an F_SETFL fcntl operation for the O_DIRECT flag.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt2-1)
bullseye: resolved (fixed in 3.16.7-ckt2-1)
forky: resolved (fixed in 3.16.7-ckt2-1)
sid: resolved (fixed in 3.16.7-ckt2-1)
trixie: resolved (fixed in 3.16.7-ckt2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-8086 Kernel: fs: ext4 race condition [fedora-all]
bugzilla·2014-10-14·CVSS 4.7
CVE-2014-8086 [MEDIUM] CVE-2014-8086 Kernel: fs: ext4 race condition [fedora-all]
CVE-2014-8086 Kernel: fs: ext4 race condition [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions of Fedora. While only
Bugzilla
CVE-2014-8086 Kernel: fs: ext4 race condition
bugzilla·2014-10-10·CVSS 4.7
CVE-2014-8086 [MEDIUM] CVE-2014-8086 Kernel: fs: ext4 race condition
CVE-2014-8086 Kernel: fs: ext4 race condition
Linux kernel built with an Ext4 file system(CONFIG_EXT4_FS) support is
vulnerable to a race condition flaw. It could occur while performing asynchronous & Direct I/O operations and fcntl(F_SETFL) call concurrently.
An unprivileged user/process could use this flaw to crash the system kernel
resulting in DoS.
Upstream fix:
-> https://git.kernel.org/linus/a41537e69b4aa43f0fea02498c2595a81267383b
Reference:
-> http://www.openwall.com/lists/oss-security/2014/10/09/25
Discussion:
Statement:
This issue does not affect the versions of Linux kernel as shipped with
Red Hat Enterprise Linux 5 and Red Hat Enterprise Linux 6.
This issue affects the version of the kernel package as shipped with
Red Hat Enterprise Linux 7 and Red Hat Enterprise MRG 2.
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0694.htmlhttp://www.openwall.com/lists/oss-security/2014/10/09/25http://www.securityfocus.com/bid/70376http://www.spinics.net/lists/linux-ext4/msg45683.htmlhttp://www.spinics.net/lists/linux-ext4/msg45685.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1151353https://exchange.xforce.ibmcloud.com/vulnerabilities/96922https://lkml.org/lkml/2014/10/8/545https://lkml.org/lkml/2014/10/9/129http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0694.htmlhttp://www.openwall.com/lists/oss-security/2014/10/09/25http://www.securityfocus.com/bid/70376http://www.spinics.net/lists/linux-ext4/msg45683.htmlhttp://www.spinics.net/lists/linux-ext4/msg45685.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1151353https://exchange.xforce.ibmcloud.com/vulnerabilities/96922https://lkml.org/lkml/2014/10/8/545https://lkml.org/lkml/2014/10/9/129
2014-10-13
Published