CVE-2014-8160

Severity
5.0MEDIUM
EPSS
2.9%
top 13.68%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 2
Latest updateMay 13

Description

net/netfilter/nf_conntrack_proto_generic.c in the Linux kernel before 3.18 generates incorrect conntrack entries during handling of certain iptables rule sets for the SCTP, DCCP, GRE, and UDP-Lite protocols, which allows remote attackers to bypass intended access restrictions via packets with disallowed port numbers.

CVSS vector

AV:N/AC:L/C:N/I:P/A:NExploitability: 10.0 | Impact: 2.9

Affected Packages11 packages

NVDlinux/linux_kernel< 3.18
Debianlinux< 3.16.7-ckt4-1+3

Also affects: Debian Linux 7.0, 8.0, Ubuntu Linux 12.04, 14.04, 14.10, Enterprise Linux 6.5, 6.6, 7.3, 7.6, 7.4, 7.5, 7.7

Patches

🔴Vulnerability Details

3
GHSA
GHSA-jr7v-xpxw-4c4v: net/netfilter/nf_conntrack_proto_generic2022-05-13
CVEList
CVE-2014-8160: net/netfilter/nf_conntrack_proto_generic2015-03-02
OSV
CVE-2014-8160: net/netfilter/nf_conntrack_proto_generic2015-03-02

📋Vendor Advisories

8
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2015-02-26
Ubuntu
Linux kernel (OMAP4) vulnerabilities2015-02-26
Ubuntu
Linux kernel vulnerabilities2015-02-26
Ubuntu
Linux kernel vulnerabilities2015-02-26
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities2015-02-26

💬Community

2
Bugzilla
CVE-2014-8160 kernel: iptables restriction bypass if a protocol handler kernel module not loaded [fedora-all]2015-01-14
Bugzilla
CVE-2014-8160 kernel: iptables restriction bypass if a protocol handler kernel module not loaded2015-01-14