CVE-2014-9710
published 2015-05-27CVE-2014-9710: The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows…
PriorityP423medium6.9CVSS 2.0
AVLACMAuNCCICAC
EPSS
0.28%
20.0th percentile
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.7-ckt9-1 (bookworm) | linux 3.16.7-ckt9-1 (bookworm) |
| linux | linux_kernel | < 3.10.83 | 3.10.83 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt9-1 | 3.16.7-ckt9-1 |
| linux | linux_kernel | >= 0 < 3.13.0-57.95 | 3.13.0-57.95 |
| linux | linux_kernel | >= 3.11 < 3.12.45 | 3.12.45 |
| linux | linux_kernel | >= 3.13 < 3.14.47 | 3.14.47 |
| linux | linux_kernel | >= 3.15 < 3.16.35 | 3.16.35 |
| linux | linux_kernel | >= 3.17 < 3.18.19 | 3.18.19 |
CVSS provenance
nvdv2.06.9MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
osv6.9MEDIUM
vendor_debian6.9MEDIUM
vendor_redhat6.9MEDIUM
vendor_ubuntu6.9MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h73c-5hr3-rgjw: The Btrfs implementation in the Linux kernel before 3
ghsa_unreviewed·2022-05-17
CVE-2014-9710 [MEDIUM] CWE-362 GHSA-h73c-5hr3-rgjw: The Btrfs implementation in the Linux kernel before 3
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit.
OSV
linux vulnerabilities
osv·2015-07-07·CVSS 6.9
CVE-2014-9710 [MEDIUM] linux vulnerabilities
linux vulnerabilities
Alexandre Oliva reported a race condition flaw in the btrfs file system's
handling of extended attributes (xattrs). A local attacker could exploit
this flaw to bypass ACLs and potentially escalate privileges.
(CVE-2014-9710)
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds check error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi
OSV
CVE-2014-9710: The Btrfs implementation in the Linux kernel before 3
osv·2015-05-27·CVSS 6.9
CVE-2014-9710 [MEDIUM] CVE-2014-9710: The Btrfs implementation in the Linux kernel before 3
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit.
OSV
linux-lts-utopic vulnerabilities
osv·2015-05-20·CVSS 6.9
CVE-2014-9710 [MEDIUM] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Alexandre Oliva reported a race condition flaw in the btrfs file system's
handling of extended attributes (xattrs). A local attacker could exploit
this flaw to bypass ACLs and potentially escalate privileges.
(CVE-2014-9710)
A memory corruption issue was discovered in AES decryption when using the
Intel AES-NI accelerated code path. A remote attacker could exploit this
flaw to cause a denial of service (system crash) or potentially escalate
privileges on Intel base machines with AEC-GCM mode IPSec security
association. (CVE-2015-3331)
A flaw was discovered in the Linux kernel's IPv4 networking when using TCP
fast open to initiate a connection. An unprivileged local user could
exploit this flaw to cause a denial of service (system crash).
(CVE-2015-3332)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 6.9
CVE-2014-9710 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Alexandre Oliva reported a race condition flaw in the btrfs file system's
handling of extended attributes (xattrs). A local attacker could exploit
this flaw to bypass ACLs and potentially escalate privileges.
(CVE-2014-9710)
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
A bounds ch
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2015-07-07·CVSS 6.9
CVE-2014-9710 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Alexandre Oliva reported a race condition flaw in the btrfs file system's
handling of extended attributes (xattrs). A local attacker could exploit
this flaw to bypass ACLs and potentially escalate privileges.
(CVE-2014-9710)
A race condition was discovered in the Linux kernel's file_handle size
verification. A local user could exploit this flaw to read potentially
sensative memory locations. (CVE-2015-1420)
A underflow error was discovered in the Linux kernel's Ozmo Devices USB
over WiFi host controller driver. A remote attacker could exploit this flaw
to cause a denial of service (system crash) or potentially execute
arbitrary code via a specially crafted packet. (CVE-2015-4001)
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2015-05-20·CVSS 6.9
CVE-2014-9710 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Alexandre Oliva reported a race condition flaw in the btrfs file system's
handling of extended attributes (xattrs). A local attacker could exploit
this flaw to bypass ACLs and potentially escalate privileges.
(CVE-2014-9710)
A memory corruption issue was discovered in AES decryption when using the
Intel AES-NI accelerated code path. A remote attacker could exploit this
flaw to cause a denial of service (system crash) or potentially escalate
privileges on Intel base machines with AEC-GCM mode IPSec security
association. (CVE-2015-3331)
A flaw was discovered in the Linux kernel's IPv4 networking when using TCP
fast open to initiate a connection. An unprivileged local user could
exploit this fla
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2015-05-20·CVSS 6.9
CVE-2014-9710 [MEDIUM] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Alexandre Oliva reported a race condition flaw in the btrfs file system's
handling of extended attributes (xattrs). A local attacker could exploit
this flaw to bypass ACLs and potentially escalate privileges.
(CVE-2014-9710)
A memory corruption issue was discovered in AES decryption when using the
Intel AES-NI accelerated code path. A remote attacker could exploit this
flaw to cause a denial of service (system crash) or potentially escalate
privileges on Intel base machines with AEC-GCM mode IPSec security
association. (CVE-2015-3331)
A flaw was discovered in the Linux kernel's IPv4 networking when using TCP
fast open to initiate a connection. An unprivileged local user could
exp
Red Hat
Kernel: fs: btrfs: non-atomic xattr replace operation
vendor_redhat·2014-11-07·CVSS 6.9
CVE-2014-9710 [MEDIUM] Kernel: fs: btrfs: non-atomic xattr replace operation
Kernel: fs: btrfs: non-atomic xattr replace operation
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit.
Statement: This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and 7. Future kernel updates for Red Hat Enterprise Linux 7 may address this issue.
Given th
Debian
CVE-2014-9710: linux - The Btrfs implementation in the Linux kernel before 3.19 does not ensure that th...
vendor_debian·2014·CVSS 6.9
CVE-2014-9710 [MEDIUM] CVE-2014-9710: linux - The Btrfs implementation in the Linux kernel before 3.19 does not ensure that th...
The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt9-1)
bullseye: resolved (fixed in 3.16.7-ckt9-1)
forky: resolved (fixed in 3.16.7-ckt9-1)
sid: resolved (fixed in 3.16.7-ckt9-1)
trixie: resolved (fixed in 3.16.7-ckt9-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-9710 Kernel: fs: btrfs: non-atomic xattr replace operation [fedora-all]
bugzilla·2015-03-24·CVSS 6.9
CVE-2014-9710 [MEDIUM] CVE-2014-9710 Kernel: fs: btrfs: non-atomic xattr replace operation [fedora-all]
CVE-2014-9710 Kernel: fs: btrfs: non-atomic xattr replace operation [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple supported versions
Bugzilla
CVE-2014-9710 Kernel: fs: btrfs: non-atomic xattr replace operation
bugzilla·2015-03-24·CVSS 6.9
CVE-2014-9710 [MEDIUM] CVE-2014-9710 Kernel: fs: btrfs: non-atomic xattr replace operation
CVE-2014-9710 Kernel: fs: btrfs: non-atomic xattr replace operation
Linux kernel built with the Btrfs Filesystem support(CONFIG_BTRFS_FS) is
vulnerable to a race condition which leaves the extended attribute(xattr)
empty for a short time window. This could be leveraged to bypass set ACLs
and potentially escalate user privileges.
An unprivileged user could use this flaw to potentially escalate privileges on
a system.
Upstream fix:
-> https://git.kernel.org/linus/5f5bc6b1e2d5a6f827bc860ef2dc5b6f365d1339
Discussion:
Statement:
This issue does not affect the versions of the kernel package as shipped with
Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2.
This issue affects the version of Linux kernel as shipped with Red Hat Enterprise Linux 6 and 7. Future kernel updates for Red H
arXiv
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
arxiv_fulltext·2022-04-26
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
The Security War in File Systems: An Empirical Study from A Vulnerability-Centric Perspective
## Abstract
This paper presents a systematic study on the security of modern file systems,
following a vulnerability-centric perspective. Specifically,
we collected 377 file system vulnerabilities committed to the CVE database in the past 20 years.
We characterize them from four dimensions that include why the vulnerabilities appear,
how the vulnerabilities can be exploited, what consequences can arise,
and how the vulnerabilities are fixed. This way, we build a deep understanding of
the attack surfaces faced by file systems, the threats imposed by the attack surfaces,
and the good and bad practices in mitigating the attacks in file systems. We envision that our study
will bring insights toward
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5f5bc6b1e2d5a6f827bc860ef2dc5b6f365d1339http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.htmlhttp://www.openwall.com/lists/oss-security/2015/03/24/11http://www.securitytracker.com/id/1032418https://bugzilla.redhat.com/show_bug.cgi?id=1205079https://github.com/torvalds/linux/commit/5f5bc6b1e2d5a6f827bc860ef2dc5b6f365d1339http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5f5bc6b1e2d5a6f827bc860ef2dc5b6f365d1339http://lists.opensuse.org/opensuse-security-announce/2015-07/msg00023.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.htmlhttp://www.openwall.com/lists/oss-security/2015/03/24/11http://www.securitytracker.com/id/1032418https://bugzilla.redhat.com/show_bug.cgi?id=1205079https://github.com/torvalds/linux/commit/5f5bc6b1e2d5a6f827bc860ef2dc5b6f365d1339
2015-05-27
Published