CVE-2014-8172
published 2015-03-16CVE-2014-8172: The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inappropriate locking approach, which…
PriorityP415medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.38%
31.0th percentile
The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inappropriate locking approach, which allows local users to cause a denial of service (soft lockup or system crash) via unspecified use of Asynchronous I/O (AIO) operations.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.13.4-1 (bookworm) | linux 3.13.4-1 (bookworm) |
| linux | linux_kernel | <= 3.12.17 | — |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
CVSS provenance
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv4.9MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2014-8172: linux - The filesystem implementation in the Linux kernel before 3.13 performs certain o...
vendor_debian·2014·CVSS 4.9
CVE-2014-8172 [MEDIUM] CVE-2014-8172: linux - The filesystem implementation in the Linux kernel before 3.13 performs certain o...
The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inappropriate locking approach, which allows local users to cause a denial of service (soft lockup or system crash) via unspecified use of Asynchronous I/O (AIO) operations.
Scope: local
bookworm: resolved (fixed in 3.13.4-1)
bullseye: resolved (fixed in 3.13.4-1)
forky: resolved (fixed in 3.13.4-1)
sid: resolved (fixed in 3.13.4-1)
trixie: resolved (fixed in 3.13.4-1)
Red Hat
kernel: soft lockup on aio
vendor_redhat·2013-11-09·CVSS 4.9
CVE-2014-8172 [MEDIUM] kernel: soft lockup on aio
kernel: soft lockup on aio
The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inappropriate locking approach, which allows local users to cause a denial of service (soft lockup or system crash) via unspecified use of Asynchronous I/O (AIO) operations.
It was found that due to excessive files_lock locking, a soft lockup could be triggered in the Linux kernel when performing asynchronous I/O operations. A local, unprivileged user could use this flaw to crash the system.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5 and 6.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kern
GHSA
GHSA-f8hg-rhq8-h2gr: The filesystem implementation in the Linux kernel before 3
ghsa_unreviewed·2022-05-17
CVE-2014-8172 [MEDIUM] GHSA-f8hg-rhq8-h2gr: The filesystem implementation in the Linux kernel before 3
The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inappropriate locking approach, which allows local users to cause a denial of service (soft lockup or system crash) via unspecified use of Asynchronous I/O (AIO) operations.
OSV
CVE-2014-8172: The filesystem implementation in the Linux kernel before 3
osv·2015-03-16·CVSS 4.9
CVE-2014-8172 [MEDIUM] CVE-2014-8172: The filesystem implementation in the Linux kernel before 3
The filesystem implementation in the Linux kernel before 3.13 performs certain operations on lists of files with an inappropriate locking approach, which allows local users to cause a denial of service (soft lockup or system crash) via unspecified use of Asynchronous I/O (AIO) operations.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=eee5cc2702929fd41cce28058dc6d6717f723f87http://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0694.htmlhttp://www.openwall.com/lists/oss-security/2015/03/09/3https://bugzilla.redhat.com/show_bug.cgi?id=1198503https://github.com/torvalds/linux/commit/eee5cc2702929fd41cce28058dc6d6717f723f87http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=eee5cc2702929fd41cce28058dc6d6717f723f87http://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0694.htmlhttp://www.openwall.com/lists/oss-security/2015/03/09/3https://bugzilla.redhat.com/show_bug.cgi?id=1198503https://github.com/torvalds/linux/commit/eee5cc2702929fd41cce28058dc6d6717f723f87
2015-03-16
Published