CVE-2014-8173
published 2015-03-16CVE-2014-8173: The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUMA systems does not properly determine…
PriorityP424high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.40%
33.2th percentile
The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUMA systems does not properly determine whether a Page Middle Directory (PMD) entry is a transparent huge-table entry, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted MADV_WILLNEED madvise system call that leverages the absence of a page-table lock.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.13.4-1 (bookworm) | linux 3.13.4-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 0 < 3.13.4-1 | 3.13.4-1 |
| linux | linux_kernel | >= 3.11 < 3.12.43 | 3.12.43 |
| linux | linux_kernel | >= 3.9 < 3.10.76 | 3.10.76 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Debian
CVE-2014-8173: linux - The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable....
vendor_debian·2014·CVSS 7.2
CVE-2014-8173 [HIGH] CVE-2014-8173: linux - The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable....
The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUMA systems does not properly determine whether a Page Middle Directory (PMD) entry is a transparent huge-table entry, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted MADV_WILLNEED madvise system call that leverages the absence of a page-table lock.
Scope: local
bookworm: resolved (fixed in 3.13.4-1)
bullseye: resolved (fixed in 3.13.4-1)
forky: resolved (fixed in 3.13.4-1)
sid: resolved (fixed in 3.13.4-1)
trixie: resolved (fixed in 3.13.4-1)
Red Hat
kernel: NULL pointer dereference in madvise(MADV_WILLNEED) support
vendor_redhat·2013-12-20·CVSS 7.2
CVE-2014-8173 [HIGH] CWE-476 kernel: NULL pointer dereference in madvise(MADV_WILLNEED) support
kernel: NULL pointer dereference in madvise(MADV_WILLNEED) support
The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUMA systems does not properly determine whether a Page Middle Directory (PMD) entry is a transparent huge-table entry, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted MADV_WILLNEED madvise system call that leverages the absence of a page-table lock.
A NULL pointer dereference flaw was found in the way the Linux kernel's madvise MADV_WILLNEED functionality handled page table locking. A local, unprivileged user could use this flaw to crash the system.
Statement: This issue does not affect the Linux kern
GHSA
GHSA-j9vf-fgh2-x3qm: The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable
ghsa_unreviewed·2022-05-17
CVE-2014-8173 [HIGH] GHSA-j9vf-fgh2-x3qm: The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable
The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUMA systems does not properly determine whether a Page Middle Directory (PMD) entry is a transparent huge-table entry, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted MADV_WILLNEED madvise system call that leverages the absence of a page-table lock.
OSV
CVE-2014-8173: The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable
osv·2015-03-16·CVSS 7.2
CVE-2014-8173 [HIGH] CVE-2014-8173: The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable
The pmd_none_or_trans_huge_or_clear_bad function in include/asm-generic/pgtable.h in the Linux kernel before 3.13 on NUMA systems does not properly determine whether a Page Middle Directory (PMD) entry is a transparent huge-table entry, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted MADV_WILLNEED madvise system call that leverages the absence of a page-table lock.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ee53664bda169f519ce3c6a22d378f0b946c8178http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0694.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1198457https://github.com/torvalds/linux/commit/ee53664bda169f519ce3c6a22d378f0b946c8178http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ee53664bda169f519ce3c6a22d378f0b946c8178http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00009.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0694.htmlhttps://bugzilla.redhat.com/show_bug.cgi?id=1198457https://github.com/torvalds/linux/commit/ee53664bda169f519ce3c6a22d378f0b946c8178
2015-03-16
Published