Back

LOW

kernel: net: use-after-free during segmentation with zerocopy

Published Mar 24, 2014

Description

Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.

Affected products

Remediation

Red Hat statement

This issue does not affect Red Hat Enterprise Linux 5 and Red Hat Enterprise MRG 2. This issue affects the Linux kernel package as shipped with Red Hat Enterprise Linux 6. Red Hat Product Security has rated this issue as having Low security impact. The risks and engineering effort associated with fixing this bug are greater than its security impact. This issue is not currently planned to be addressed in future kernel updates for Red Hat Enterprise Linux 6. For additional information, refer to the Issue Severity Classification: https://access.redhat.com/security/updates/classification/.

Metrics

Weaknesses (1)

References (11)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Mar 24, 2014
Updated Aug 6, 2024
Reserved Dec 3, 2013
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Mar 10, 2014