[Forgot Password]
Login  Register Subscribe

30430

 
 

423868

 
 

247862

 
 

909

 
 

194603

 
 

282

Paid content will be excluded from the download.


Download | Alert*
CVE
view JSON

CVE-2014-8559Date: (C)2014-11-13   (M)2024-04-17


The d_walk function in fs/dcache.c in the Linux kernel through 3.17.2 does not properly maintain the semantics of rename_lock, which allows local users to cause a denial of service (deadlock and system hang) via a crafted application.

CVSS Score and Metrics +CVSS Score and Metrics -

CVSS V3 Severity:CVSS V2 Severity:
CVSS Score : 5.5CVSS Score : 4.9
Exploit Score: 1.8Exploit Score: 3.9
Impact Score: 3.6Impact Score: 6.9
 
CVSS V3 Metrics:CVSS V2 Metrics:
Attack Vector: LOCALAccess Vector: LOCAL
Attack Complexity: LOWAccess Complexity: LOW
Privileges Required: LOWAuthentication: NONE
User Interaction: NONEConfidentiality: NONE
Scope: UNCHANGEDIntegrity: NONE
Confidentiality: NONEAvailability: COMPLETE
Integrity: NONE 
Availability: HIGH 
  
Reference:
SECTRACK-1034051
SECUNIA-62801
BID-70854
DSA-3170
RHSA-2015:1976
RHSA-2015:1978
SUSE-SU-2015:0178
SUSE-SU-2015:0481
SUSE-SU-2015:0529
SUSE-SU-2015:0736
USN-2492-1
USN-2493-1
USN-2515-1
USN-2516-1
USN-2517-1
USN-2518-1
https://lkml.org/lkml/2014/10/25/171
https://lkml.org/lkml/2014/10/25/179
http://www.openwall.com/lists/oss-security/2014/10/30/7
http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2015-2719645.html
https://bugzilla.redhat.com/show_bug.cgi?id=1159313
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=946e51f2bf37f1656916eb75bd0742ba33983c28
https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=ca5358ef75fc69fee5322a38a340f5739d997c10
https://support.f5.com/csp/article/K05211147
openSUSE-SU-2015:0566
openSUSE-SU-2015:0714

CPE    6
cpe:/o:opensuse:opensuse:13.1
cpe:/o:novell:suse_linux_enterprise_desktop:12.0
cpe:/o:canonical:ubuntu_linux:12.04::~~esm~~~
cpe:/o:canonical:ubuntu_linux:14.10
...
CWE    1
CWE-400
OVAL    34
oval:org.secpod.oval:def:108204
oval:org.secpod.oval:def:702401
oval:org.secpod.oval:def:23615
oval:org.secpod.oval:def:702399
...

© SecPod Technologies