CVE-2014-8709
published 2014-11-10CVE-2014-8709: The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote…
PriorityP427medium5CVSS 2.0
AVNACLAuNCPINAN
EPSS
4.52%
90.6th percentile
The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading packets.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.14.2-1 (bookworm) | linux 3.14.2-1 (bookworm) |
| android | — | — | |
| linux | linux_kernel | <= 3.13.4 | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 3.14.2-1 | 3.14.2-1 |
| linux | linux_kernel | >= 0 < 3.14.2-1 | 3.14.2-1 |
| linux | linux_kernel | >= 0 < 3.14.2-1 | 3.14.2-1 |
| linux | linux_kernel | >= 0 < 3.14.2-1 | 3.14.2-1 |
CVSS provenance
nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:P/I:N/A:N
osv5.0MEDIUM
vendor_ubuntu7.5HIGH
vendor_debian5.0MEDIUM
vendor_redhat5.0MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2014-8709: Android Security Bulletin 2017-03-01
CVE: CVE-2014-8709
Severity: HIGH
References: A-34077221
Upstream kernel
vendor_android·2017-03-01·CVSS 5.0
CVE-2014-8709 [MEDIUM] CVE-2014-8709: Android Security Bulletin 2017-03-01
CVE: CVE-2014-8709
Severity: HIGH
References: A-34077221
Upstream kernel
Android Security Bulletin 2017-03-01
CVE: CVE-2014-8709
Severity: HIGH
References: A-34077221
Upstream kernel
Ubuntu
Linux kernel (EC2) vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.5
CVE-2014-3673 [HIGH] Linux kernel (EC2) vulnerabilities
Title: Linux kernel (EC2) vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
A flaw in the handling of malformed ASCONF chunks by SCTP (Stream Control
Transmission Protocol) implementation in the Linux kernel was discovered. A
remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2014-3673)
A flaw in the handling of duplicate ASCONF chunks by SCTP (Stream Control
Transmission Protocol) implementation in the Linux
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.5
CVE-2014-3673 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
A flaw in the handling of malformed ASCONF chunks by SCTP (Stream Control
Transmission Protocol) implementation in the Linux kernel was discovered. A
remote attacker could exploit this flaw to cause a denial of service
(system crash). (CVE-2014-3673)
A flaw in the handling of duplicate ASCONF chunks by SCTP (Stream Control
Transmission Protocol) implementation in the Linux kerne
Red Hat
kernel: net: mac80211: plain text information leak
vendor_redhat·2014-11-06·CVSS 5.0
CVE-2014-8709 [MEDIUM] kernel: net: mac80211: plain text information leak
kernel: net: mac80211: plain text information leak
The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading packets.
An information leak flaw was found in the Linux kernel's IEEE 802.11 wireless networking implementation. When software encryption was used, a remote attacker could use this flaw to leak up to 8 bytes of plaintext.
Statement: This issue did not affect the version of the kernel package as shipped with Red Hat Enterprise MRG 2.
This issue affects the versions of Linux kernel as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 5 is now in Production 3 Phase of the support and maintenance life cycle
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-05-27·CVSS 4.9
CVE-2013-4483 [MEDIUM] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Linux kernel's pseudo tty (pty) device. An
unprivileged user could exploit this flaw to cause a denial of service
(system crash) or potentially gain administrator privileges.
(CVE-2014-0196)
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in the handling of ioctl commands by the
floppy disk driver in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges if the floppy disk
module is loaded. (CVE-2014-1737)
A
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-05-26·CVSS 4.9
CVE-2013-4483 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Matthew Daley reported an information leak in the floppy disk driver of the
Linux kernel. An unprivileged local user could exploit this flaw to obtain
potentially sensitive information from kernel memory. (CVE-2014-1738)
Matthew Daley reported a flaw in the handling of ioctl commands by the
floppy disk driver in the Linux kernel. An unprivileged local user could
exploit this flaw to gain administrative privileges if the floppy disk
module is loaded. (CVE-2014-1737)
A flaw was discovered in the Linux kernel's IPC reference counting. An
unprivileged local user could exploit this flaw to cause a denial of
service (OOM system crash). (CVE-2013-4483)
Al Viro discovered an error in how CIFS in the
Ubuntu
Linux kernel (Quantal HWE) vulnerabilities
vendor_ubuntu·2014-04-26·CVSS 7.4
CVE-2014-0049 [HIGH] Linux kernel (Quantal HWE) vulnerabilities
Title: Linux kernel (Quantal HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Kernel Virtual Machine (KVM) subsystem of the
Linux kernel. A guest OS user could exploit this flaw to execute arbitrary
code on the host OS. (CVE-2014-0049)
Al Viro discovered an error in how CIFS in the Linux kernel handles
uncached write operations. An unprivileged local user could exploit this
flaw to cause a denial of service (system crash), obtain sensitive
information from kernel memory, or possibly gain privileges.
(CVE-2014-0069)
Jouni Malinen reported a flaw in the handling of fragmentation in the
mac8Linux subsystem of the kernel. A remote attacker could exploit this
flaw to obtain potential sensitive cleartext information by reading
packe
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities
vendor_ubuntu·2014-04-26·CVSS 7.4
CVE-2014-0049 [HIGH] Linux kernel (Saucy HWE) vulnerabilities
Title: Linux kernel (Saucy HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Kernel Virtual Machine (KVM) subsystem of the
Linux kernel. A guest OS user could exploit this flaw to execute arbitrary
code on the host OS. (CVE-2014-0049)
Al Viro discovered an error in how CIFS in the Linux kernel handles
uncached write operations. An unprivileged local user could exploit this
flaw to cause a denial of service (system crash), obtain sensitive
information from kernel memory, or possibly gain privileges.
(CVE-2014-0069)
Jouni Malinen reported a flaw in the handling of fragmentation in the
mac8Linux subsystem of the kernel. A remote attacker could exploit this
flaw to obtain potential sensitive cleartext information by reading
packets
Debian
CVE-2014-8709: linux - The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before ...
vendor_debian·2014·CVSS 5.0
CVE-2014-8709 [MEDIUM] CVE-2014-8709: linux - The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before ...
The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading packets.
Scope: local
bookworm: resolved (fixed in 3.14.2-1)
bullseye: resolved (fixed in 3.14.2-1)
forky: resolved (fixed in 3.14.2-1)
sid: resolved (fixed in 3.14.2-1)
trixie: resolved (fixed in 3.14.2-1)
GHSA
GHSA-g4q7-7383-w67v: The ieee80211_fragment function in net/mac80211/tx
ghsa_unreviewed·2022-05-17
CVE-2014-8709 [MEDIUM] CWE-200 GHSA-g4q7-7383-w67v: The ieee80211_fragment function in net/mac80211/tx
The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading packets.
OSV
CVE-2014-8709: The ieee80211_fragment function in net/mac80211/tx
osv·2014-11-10·CVSS 5.0
CVE-2014-8709 [MEDIUM] CVE-2014-8709: The ieee80211_fragment function in net/mac80211/tx
The ieee80211_fragment function in net/mac80211/tx.c in the Linux kernel before 3.13.5 does not properly maintain a certain tail pointer, which allows remote attackers to obtain sensitive cleartext information by reading packets.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=338f977f4eb441e69bb9a46eaa0ac715c931a67fhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1272.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.13.5http://www.openwall.com/lists/oss-security/2014/11/09/1http://www.securityfocus.com/bid/70965http://www.securitytracker.com/id/1037968https://exchange.xforce.ibmcloud.com/vulnerabilities/98922https://github.com/torvalds/linux/commit/338f977f4eb441e69bb9a46eaa0ac715c931a67fhttps://source.android.com/security/bulletin/2017-03-01.htmlhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=338f977f4eb441e69bb9a46eaa0ac715c931a67fhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-04/msg00000.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-1272.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.13.5http://www.openwall.com/lists/oss-security/2014/11/09/1http://www.securityfocus.com/bid/70965http://www.securitytracker.com/id/1037968https://exchange.xforce.ibmcloud.com/vulnerabilities/98922https://github.com/torvalds/linux/commit/338f977f4eb441e69bb9a46eaa0ac715c931a67fhttps://source.android.com/security/bulletin/2017-03-01.html
2014-11-10
Published