CVE-2014-9914
published 2017-02-07CVE-2014-9914: Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause…
PriorityP338high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.27%
19.6th percentile
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.2-1 (bookworm) | linux 3.16.2-1 (bookworm) |
| android | <= 7.1.1 | — | |
| android | — | — | |
| linux | linux_kernel | >= 0 < 3.16.2-1 | 3.16.2-1 |
| linux | linux_kernel | >= 0 < 3.16.2-1 | 3.16.2-1 |
| linux | linux_kernel | >= 0 < 3.16.2-1 | 3.16.2-1 |
| linux | linux_kernel | >= 0 < 3.16.2-1 | 3.16.2-1 |
| linux | linux_kernel | >= 3.11 < 3.12.23 | 3.12.23 |
| linux | linux_kernel | >= 3.13 < 3.14.9 | 3.14.9 |
| linux | linux_kernel | >= 3.15 < 3.15.2 | 3.15.2 |
| linux | linux_kernel | >= 3.7.8 < 3.10.45 | 3.10.45 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Android
CVE-2014-9914: Android Security Bulletin 2017-02-01
CVE: CVE-2014-9914
Severity: CRITICAL
References: A-32882659
Upstream kernel
vendor_android·2017-02-01·CVSS 7.8
CVE-2014-9914 [HIGH] CVE-2014-9914: Android Security Bulletin 2017-02-01
CVE: CVE-2014-9914
Severity: CRITICAL
References: A-32882659
Upstream kernel
Android Security Bulletin 2017-02-01
CVE: CVE-2014-9914
Severity: CRITICAL
References: A-32882659
Upstream kernel
Red Hat
kernel: Race condition in the ip4_datagram_release_cb function
vendor_redhat·2014-06-10·CVSS 7.8
CVE-2014-9914 [HIGH] CWE-362 kernel: Race condition in the ip4_datagram_release_cb function
kernel: Race condition in the ip4_datagram_release_cb function
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.
A race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.
Statement: This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux
Debian
CVE-2014-9914: linux - Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in...
vendor_debian·2014·CVSS 7.8
CVE-2014-9914 [HIGH] CVE-2014-9914: linux - Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in...
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.
Scope: local
bookworm: resolved (fixed in 3.16.2-1)
bullseye: resolved (fixed in 3.16.2-1)
forky: resolved (fixed in 3.16.2-1)
sid: resolved (fixed in 3.16.2-1)
trixie: resolved (fixed in 3.16.2-1)
GHSA
GHSA-63m2-xjhc-qq8p: Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram
ghsa_unreviewed·2022-05-17
CVE-2014-9914 [HIGH] CWE-362 GHSA-63m2-xjhc-qq8p: Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.
OSV
CVE-2014-9914: Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram
osv·2017-02-07·CVSS 7.8
CVE-2014-9914 [HIGH] CVE-2014-9914: Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram
Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9709674e68646cee5a24e3000b3558d25412203ahttp://source.android.com/security/bulletin/2017-02-01.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.15.2http://www.securityfocus.com/bid/96100http://www.securitytracker.com/id/1037798https://github.com/torvalds/linux/commit/9709674e68646cee5a24e3000b3558d25412203ahttp://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9709674e68646cee5a24e3000b3558d25412203ahttp://source.android.com/security/bulletin/2017-02-01.htmlhttp://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.15.2http://www.securityfocus.com/bid/96100http://www.securitytracker.com/id/1037798https://github.com/torvalds/linux/commit/9709674e68646cee5a24e3000b3558d25412203a
2017-02-07
Published