kernel: cifs: incorrect handling of bogus user pointers during uncached writes
Published Feb 28, 2014
7.2
HIGHCVSS 2.0
EPSS 0.41%
Description
The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes, which allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory corruption and system crash), or possibly gain privileges via a writev system call with a crafted pointer.
Affected products
No data.
Configuration 1
- < 3.2.57
- ≥ 3.3 · < 3.4.83
- ≥ 3.5 · < 3.10.33
- ≥ 3.11 · < 3.12.14
- ≥ 3.13 · < 3.13.6
Configuration 2
- 11
- 11
- 11
- 11
Configuration 3
- 6.0
- 6.5
- 6.0
- 6.5
- 6.5
- 6.0
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-431.11.2.el6
Fixed · RHSA-2014:0328
Red Hat Enterprise MRG 2
kernel-rt-0:3.10.33-rt32.33.el6rt
Fixed · RHSA-2014:0439
Red Hat Enterprise Linux 5
kernel
Not affected
Red Hat Enterprise Linux 7
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-431.11.2.el6 | Fixed | RHSA-2014:0328 |
| Red Hat Enterprise MRG 2 | kernel-rt-0:3.10.33-rt32.33.el6rt | Fixed | RHSA-2014:0439 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 5.
References (11)
- http://article.gmane.org/gmane.linux.kernel.cifs/9401 mailing-listx_refsource_MLISTBroken Link
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5d81de8e8667da7135d3a32a964087c0faf5483f x_refsource_CONFIRMBroken Link
- http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00026.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0328.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/02/17/4 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.securityfocus.com/bid/65588 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2014-0069 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1064253 x_refsource_CONFIRMIssue TrackingThird Party Advisory
- https://github.com/torvalds/linux/commit/5d81de8e8667da7135d3a32a964087c0faf5483f x_refsource_CONFIRMPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0069
- https://www.cve.org/CVERecord?id=CVE-2014-0069
Change history (0)
No recorded changes yet.