CVE-2014-9644
published 2015-03-02CVE-2014-9644: The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a…
PriorityP414low2.1CVSS 2.0
AVLACLAuNCNIPAN
EPSS
0.55%
42.8th percentile
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | debian_linux | — | — |
| debian | debian_linux | — | — |
| debian | linux | < linux 3.16.7-ckt4-2 (bookworm) | linux 3.16.7-ckt4-2 (bookworm) |
| linux | linux_kernel | < 3.18.5 | 3.18.5 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-2 | 3.16.7-ckt4-2 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-2 | 3.16.7-ckt4-2 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-2 | 3.16.7-ckt4-2 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt4-2 | 3.16.7-ckt4-2 |
| linux | linux_kernel | >= 0 < 3.13.0-48.80 | 3.13.0-48.80 |
| oracle | linux | — | — |
| oracle | linux | — | — |
| oracle | linux | — | — |
CVSS provenance
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:P/A:N
osv2.1LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-7h46-6772-ccxh: The Crypto API in the Linux kernel before 3
ghsa_unreviewed·2022-05-13·CVSS 2.1
CVE-2013-7421 [LOW] CWE-269 GHSA-7h46-6772-ccxh: The Crypto API in the Linux kernel before 3
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.
GHSA
GHSA-m5x6-353v-hmg2: The Crypto API in the Linux kernel before 3
ghsa_unreviewed·2022-05-13·CVSS 2.1
CVE-2014-9644 [LOW] CWE-269 GHSA-m5x6-353v-hmg2: The Crypto API in the Linux kernel before 3
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.
OSV
linux-lts-utopic vulnerabilities
osv·2015-03-24·CVSS 2.1
CVE-2013-7421 [LOW] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
A flaw was discovered in the crypto subsystem when screening module names
for automatic module loading if the name contained a valid crypto module
name, eg. vfat(aes). A local user could exploit this flaw to load installed
kernel modules, increasing the attack surface and potentially using this to
gain administrative privileges. (CVE-2014-9644)
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
(Stream Control Transmission Protocol) subsystem during INIT c
OSV
linux vulnerabilities
osv·2015-03-24·CVSS 2.1
CVE-2015-0274 [LOW] linux vulnerabilities
linux vulnerabilities
Eric Windisch discovered flaw in how the Linux kernel's XFS file system
replaces remote attributes. A local access with access to an XFS file
system could exploit this flaw to escalate their privileges.
(CVE-2015-0274)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-7822)
A flaw was discovered in the crypto subsystem when screening module names
for au
OSV
CVE-2014-9644: The Crypto API in the Linux kernel before 3
osv·2015-03-02·CVSS 2.1
CVE-2014-9644 [LOW] CVE-2014-9644: The Crypto API in the Linux kernel before 3
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.
OSV
CVE-2013-7421: The Crypto API in the Linux kernel before 3
osv·2015-03-02·CVSS 2.1
CVE-2013-7421 [LOW] CVE-2013-7421: The Crypto API in the Linux kernel before 3
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Eric Windisch discovered flaw in how the Linux kernel's XFS file system
replaces remote attributes. A local access with access to an XFS file
system could exploit this flaw to escalate their privileges.
(CVE-2015-0274)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-7822)
A flaw
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
A flaw was discovered in the crypto subsystem when screening module names
for automatic module loading if the name contained a valid crypto module
name, eg. vfat(aes). A local user could exploit this flaw to load installed
kernel modules, increasing the attack surface and potentially using this to
gain administrative privileges. (CVE-2014-9644)
Sun Baoliang discovered a use after free flaw in the Linux kernel's SCTP
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Eric Windisch discovered flaw in how the Linux kernel's XFS file system
replaces remote attributes. A local access with access to an XFS file
system could exploit this flaw to escalate their privileges.
(CVE-2015-0274)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
The Linux kernel's splice system call did not correctly validate its
parameters. A local, unprivileged user could exploit this flaw to cause a
denial of service (system crash). (CVE-2014-
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-03-24·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
A flaw was discovered in the crypto subsystem when screening module names
for automatic module loading if the name contained a valid crypto module
name, eg. vfat(aes). A local user could exploit this flaw to load installed
kernel modules, increasing the attack surface and potentially using this to
gain administrative privileges. (CVE-2014-9644)
Sun Baoliang discovered a use after free flaw in the Linux
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
Andy Lutomirski discovered a flaw in how the Linux kernel handles
pivot_root when used with a chro
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-02-26·CVSS 2.1
CVE-2013-7421 [LOW] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
A flaw was discovered in the Kernel Virtual Machine's (KVM) emulation of
the SYSTENTER instruction when the guest OS does not initialize the
SYSENTER MSRs. A guest OS user could exploit this flaw to cause a denial of
service of the guest OS (crash) or potentially gain privileges on the guest
OS. (CVE-2015-0239)
A flaw was discovered in the automatic loading of modules in the crypto
subsystem of the Linux kernel. A local user could exploit this flaw to load
installed kernel modules, increasing the attack surface and potentially
using this to gain administrative privileges. (CVE-2013-7421)
Andy Lutomirski discovered a flaw in how the Linux kernel handles
pivot_root when used with a chroot direc
Debian
CVE-2014-9644: linux - The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbi...
vendor_debian·2014·CVSS 2.1
CVE-2014-9644 [LOW] CVE-2014-9644: linux - The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbi...
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt4-2)
bullseye: resolved (fixed in 3.16.7-ckt4-2)
forky: resolved (fixed in 3.16.7-ckt4-2)
sid: resolved (fixed in 3.16.7-ckt4-2)
trixie: resolved (fixed in 3.16.7-ckt4-2)
Red Hat
kernel: crypto api unprivileged arbitrary module load via request_module()
vendor_redhat·2013-03-04·CVSS 2.1
CVE-2014-9644 [LOW] CWE-749 kernel: crypto api unprivileged arbitrary module load via request_module()
kernel: crypto api unprivileged arbitrary module load via request_module()
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.
A flaw was found in the way the Linux kernel's Crypto subsystem handled automatic loading of kernel modules. A local user could use this flaw to load any installed kernel module, and thus increase the attack surface of the running kernel.
Statement: This issue did not affect the versions of the kernel as shipped
with Red Hat Enterprise Linux 4, 5, and 6.
This issue affects the versions of the Linux as shipped w
Red Hat
kernel: crypto api unprivileged arbitrary module load via request_module()
vendor_redhat·2013-03-04·CVSS 2.1
CVE-2013-7421 [LOW] CWE-749 kernel: crypto api unprivileged arbitrary module load via request_module()
kernel: crypto api unprivileged arbitrary module load via request_module()
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.
A flaw was found in the way the Linux kernel's Crypto subsystem handled automatic loading of kernel modules. A local user could use this flaw to load any installed kernel module, and thus increase the attack surface of the running kernel.
Statement: This issue did not affect the versions of the kernel as shipped
with Red Hat Enterprise Linux 4, 5, and 6.
This issue affects the versions of the Linux as shipped with Red Hat Enterprise Linux 7. Red Hat Product Security has rated this is
Debian
CVE-2013-7421: linux - The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbi...
vendor_debian·2013·CVSS 2.1
CVE-2013-7421 [LOW] CVE-2013-7421: linux - The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbi...
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a module name in the salg_name field, a different vulnerability than CVE-2014-9644.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt4-2)
bullseye: resolved (fixed in 3.16.7-ckt4-2)
forky: resolved (fixed in 3.16.7-ckt4-2)
sid: resolved (fixed in 3.16.7-ckt4-2)
trixie: resolved (fixed in 3.16.7-ckt4-2)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-1855 ruby: OpenSSL extension hostname matching implementation violates RFC 6125
bugzilla·2015-04-08·CVSS 4.3
CVE-2015-1855 [MEDIUM] CVE-2015-1855 ruby: OpenSSL extension hostname matching implementation violates RFC 6125
CVE-2015-1855 ruby: OpenSSL extension hostname matching implementation violates RFC 6125
Ruby OpenSSL hostname matching implementation violates RFC 6125.
- Wildcard matching code allowed multiple wildcards (e.g. *.*.*)
- Wildcards were mishandled for IDNA names (ala CVE-2014-1492)
Upstream patch:
https://github.com/ruby/openssl/commit/e9a7bcb8bf2902f907c148a00bbcf21d3fa79596
Discussion:
Created ruby tracking bugs for this issue:
Affects: fedora-all [bug 1209982]
---
Fixed upstream in Ruby versions: 2.0.0p645, 2.1.6, and 2.2.2
Upstream bug report:
https://bugs.ruby-lang.org/issues/9644
Upstream commit in ruby SVN:
http://svn.ruby-lang.org/cgi-bin/viewvc.cgi?view=revision&revision=50292
External References:
https://www.ruby-lang.org/en/news/2015/04/13/ruby-openssl-hostname-matchin
Bugzilla
CVE-2014-9644 Linux kernel: crypto api unprivileged arbitrary module load via request_module() [fedora-all]
bugzilla·2015-02-10·CVSS 2.1
CVE-2014-9644 [LOW] CVE-2014-9644 Linux kernel: crypto api unprivileged arbitrary module load via request_module() [fedora-all]
CVE-2014-9644 Linux kernel: crypto api unprivileged arbitrary module load via request_module() [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects m
Bugzilla
CVE-2014-9644 Linux kernel: crypto api unprivileged arbitrary module load via request_module()
bugzilla·2015-02-09·CVSS 2.1
CVE-2014-9644 [LOW] CVE-2014-9644 Linux kernel: crypto api unprivileged arbitrary module load via request_module()
CVE-2014-9644 Linux kernel: crypto api unprivileged arbitrary module load via request_module()
Linux Kernel 2.6.38 through 3.18 are affected by a flaw in the Crypto API that allows any local user to load any installed kernel module on systems where CONFIG_CRYPTO_USER_API=y by abusing the request_module() call.
In the introduction of Crypto User API in the linux kernel in version 2.6.38 introduced a defect which granted userspace applications to load kernel modules on the system, by abusing the request_module() kernel call. This patch also fixes the
The kernel accomplished loading algorithms by searching for the matching kernel module name provided when a user attempts to use a socket via the AF_ALG socket type. Initially there were no checks involved in validating the name of the module
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4943ba16bbc2db05115707b3ff7b4874e9e3c560http://rhn.redhat.com/errata/RHSA-2016-0068.htmlhttp://www.debian.org/security/2015/dsa-3170http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.5http://www.mandriva.com/security/advisories?name=MDVSA-2015:057http://www.mandriva.com/security/advisories?name=MDVSA-2015:058http://www.openwall.com/lists/oss-security/2015/01/24/4http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72320http://www.ubuntu.com/usn/USN-2513-1http://www.ubuntu.com/usn/USN-2514-1http://www.ubuntu.com/usn/USN-2543-1http://www.ubuntu.com/usn/USN-2544-1http://www.ubuntu.com/usn/USN-2545-1http://www.ubuntu.com/usn/USN-2546-1https://bugzilla.redhat.com/show_bug.cgi?id=1190546https://github.com/torvalds/linux/commit/4943ba16bbc2db05115707b3ff7b4874e9e3c560https://plus.google.com/+MathiasKrause/posts/PqFCo4bfrWuhttp://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4943ba16bbc2db05115707b3ff7b4874e9e3c560http://rhn.redhat.com/errata/RHSA-2016-0068.htmlhttp://www.debian.org/security/2015/dsa-3170http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.18.5http://www.mandriva.com/security/advisories?name=MDVSA-2015:057http://www.mandriva.com/security/advisories?name=MDVSA-2015:058http://www.openwall.com/lists/oss-security/2015/01/24/4http://www.oracle.com/technetwork/topics/security/linuxbulletinjan2016-2867209.htmlhttp://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.htmlhttp://www.securityfocus.com/bid/72320http://www.ubuntu.com/usn/USN-2513-1http://www.ubuntu.com/usn/USN-2514-1http://www.ubuntu.com/usn/USN-2543-1http://www.ubuntu.com/usn/USN-2544-1http://www.ubuntu.com/usn/USN-2545-1http://www.ubuntu.com/usn/USN-2546-1https://bugzilla.redhat.com/show_bug.cgi?id=1190546https://github.com/torvalds/linux/commit/4943ba16bbc2db05115707b3ff7b4874e9e3c560https://plus.google.com/+MathiasKrause/posts/PqFCo4bfrWu
2015-03-02
Published