CVE-2014-8181
published 2019-11-06CVE-2014-8181: The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
PriorityP424medium5.5CVSS 3.1
AVLACLPRLUINSUCHINAN
EPSS
0.36%
28.1th percentile
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | — | — |
| red_hat | enterprise_linux | — | — |
| redhat | enterprise_linux | — | — |
| redhat | enterprise_mrg | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
vendor_debian5.5LOW
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: scsi: do not fill dirty page content in the SG_IO buffer
vendor_redhat·2016-05-13·CVSS 5.5
CVE-2014-8181 [MEDIUM] CWE-665 kernel: scsi: do not fill dirty page content in the SG_IO buffer
kernel: scsi: do not fill dirty page content in the SG_IO buffer
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5,6.
This issue affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and MRG-2. This has been rated as having Low security impact as exploiting it requires privileged access and is not currently planned to be addressed in future updates. For additional information, refer to the Red Hat Enterprise Linux Life Cycle: https://access.redhat.com/support/policy/updates/errata/.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (
Debian
CVE-2014-8181: linux - The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data f...
vendor_debian·2014·CVSS 5.5
CVE-2014-8181 [MEDIUM] CVE-2014-8181: linux - The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data f...
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
Scope: local
bookworm: resolved
bullseye: resolved
forky: resolved
sid: resolved
trixie: resolved
GHSA
GHSA-8qfp-mxrj-h5cx: The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace
ghsa_unreviewed·2022-05-17
CVE-2014-8181 [LOW] CWE-665 GHSA-8qfp-mxrj-h5cx: The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace
The kernel in Red Hat Enterprise Linux 7 and MRG-2 does not clear garbage data for SG_IO buffer, which may leaking sensitive information to userspace.
No detection rules found.
No public exploits indexed.
2019-11-06
Published