[Forgot Password]
Login  Register Subscribe

30479

 
 

423868

 
 

248149

 
 

909

 
 

194803

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-3940Date: (C)2014-06-16   (M)2024-04-17


The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.c and mm/mempolicy.c.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V2 Severity:
CVSS Score : 4.0
Exploit Score: 1.9
Impact Score: 6.9
 
CVSS V2 Metrics:
Access Vector: LOCAL
Access Complexity: HIGH
Authentication: NONE
Confidentiality: NONE
Integrity: NONE
Availability: COMPLETE
  
Reference:
SECUNIA-59011
SECUNIA-61310
BID-67786
RHSA-2015:0290
RHSA-2015:1272
https://lkml.org/lkml/2014/3/18/784
http://www.openwall.com/lists/oss-security/2014/06/02/5
https://bugzilla.redhat.com/show_bug.cgi?id=1104097
https://support.f5.com/kb/en-us/solutions/public/15000/600/sol15685.html

CPE    14
cpe:/o:linux:linux_kernel:3.14:rc8
cpe:/o:linux:linux_kernel:3.14:rc7
cpe:/o:linux:linux_kernel:3.14:rc6
cpe:/o:linux:linux_kernel:3.14:rc5
...
CWE    1
CWE-362
OVAL    39
oval:org.secpod.oval:def:108483
oval:org.secpod.oval:def:108880
oval:org.secpod.oval:def:108760
oval:org.secpod.oval:def:108666
...

© SecPod Technologies