cbcvebase.
CVE-2014-8173
published 2015-03-16

CVE-2014-8173: The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUMA systems does not properly determine…

PriorityP424high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.40%
33.2th percentile
The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUMA systems does not properly determine whether a Page Middle Directory (PMD) entry is a transparent huge-table entry, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted MADV_WILLNEED madvise system call that leverages the absence of a page-table lock.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.13.4-1 (bookworm)linux 3.13.4-1 (bookworm)
linuxlinux_kernel>= 0 < 3.13.4-13.13.4-1
linuxlinux_kernel>= 0 < 3.13.4-13.13.4-1
linuxlinux_kernel>= 0 < 3.13.4-13.13.4-1
linuxlinux_kernel>= 0 < 3.13.4-13.13.4-1
linuxlinux_kernel>= 3.11 < 3.12.433.12.43
linuxlinux_kernel>= 3.9 < 3.10.763.10.76

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.