kernel: pty layer race condition leading to memory corruption
Published May 7, 2014 ·Due Jun 2, 2023
5.5
MEDIUMCVSS 3.1
EPSS 22.48%
Description
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
Affected products
No data.
Configuration 1
- > 2.6.31 · < 3.2.59
- ≥ 3.3 · < 3.4.91
- ≥ 3.5 · < 3.10.40
- ≥ 3.11 · < 3.12.20
- ≥ 3.13 · < 3.14.4
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
- 2.6.31
Configuration 2
- 6.0
- 7.0
Configuration 3
- 6.0
- 6.3
- 6.4
- 6.3
Configuration 4
- 11
- 11
- 11
- 11
Configuration 6
- 10.04
- 12.04
- 12.10
- 13.10
- 14.04
Configuration 7
- ≥ 11.1.0 · ≤ 11.5.1
- ≥ 11.3.0 · ≤ 11.5.1
- ≥ 11.1.0 · ≤ 11.5.1
- ≥ 11.4.0 · ≤ 11.5.1
- ≥ 11.1.0 · ≤ 11.5.1
- ≥ 11.1.0 · ≤ 11.3.0
- ≥ 11.1.0 · ≤ 11.5.1
- ≥ 11.1.0 · ≤ 11.5.1
- ≥ 11.1.0 · ≤ 11.5.1
- ≥ 11.3.0 · ≤ 11.5.1
- ≥ 11.1.0 · ≤ 11.4.1
- ≥ 11.1.0 · ≤ 11.3.0
- ≥ 11.1.0 · ≤ 11.3.0
- 4.5.0
- 4.6.0
- ≥ 4.0.0 · ≤ 4.5.0
- 1.0.0
- ≥ 4.2.0 · ≤ 4.5.0
- ≥ 4.0.0 · ≤ 4.5.0
- 3.1.0
- 3.1.1
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-358.6.1.el6
Fixed · RHSA-2013:0744
Red Hat Enterprise Linux 6.2 Advanced Update Support
kernel-0:2.6.32-220.51.1.el6
Fixed · RHSA-2014:0520
Red Hat Enterprise Linux 6.3 EUS - Server and Compute Node Only
kernel-0:2.6.32-279.43.2.el6
Fixed · RHSA-2014:0512
Red Hat Enterprise Linux 7
kernel-0:3.10.0-123.1.2.el7
Fixed · RHSA-2014:0678
Red Hat Enterprise MRG 2
kernel-rt-0:3.10.33-rt32.34.el6rt
Fixed · RHSA-2014:0557
Red Hat Enterprise Linux 5
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-358.6.1.el6 | Fixed | RHSA-2013:0744 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | kernel-0:2.6.32-220.51.1.el6 | Fixed | RHSA-2014:0520 |
| Red Hat Enterprise Linux 6.3 EUS - Server and Compute Node Only | kernel-0:2.6.32-279.43.2.el6 | Fixed | RHSA-2014:0512 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-123.1.2.el7 | Fixed | RHSA-2014:0678 |
| Red Hat Enterprise MRG 2 | kernel-rt-0:3.10.33-rt32.34.el6rt | Fixed | RHSA-2014:0557 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue did not affect the versions of the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. This issue affected the versions of the Linux kernel packages as shipped with Red Hat Enterprise Linux 6 prior to version kernel-2.6.32-358.6.1.el6, released via RHSA-2013:0744 (https://rhn.redhat.com/errata/RHSA-2013-0744.html). That update added a backport of the upstream commit c56a00a165, which avoided this issue. This flaw requires local system access to be exploited. We are currently not aware of any working exploit for Red Hat Enterprise Linux 6 or Red Hat Enterprise MRG 2.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
No CVSS v3.0 score for this CVE.
AV:L/AC:M/Au:N/C:C/I:C/A:C
Date Added
May 12, 2023
Patch Due
Jun 2, 2023
Required Action
The impacted product is end-of-life and should be disconnected if still in use.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
ActiveAutomatable
NoTechnical Impact
PartialDecision
n/aAssessed Feb 7, 2025 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (30 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 22.48% (0.22475) | 97.64th | v5 (v2026.06.15) |
| Jun 15, 2026 | 22.48% (0.22475) | 97.40th | v5 (v2026.06.15) |
| May 21, 2026 | 49.91% (0.49911) | 97.85th | v4 (v2025.03.14) |
| May 20, 2026 | 47.84% (0.47836) | 97.75th | v4 (v2025.03.14) |
| May 19, 2026 | 49.31% (0.49311) | 97.82th | v4 (v2025.03.14) |
| May 18, 2026 | 41.60% (0.41596) | 97.46th | v4 (v2025.03.14) |
| May 16, 2026 | 39.36% (0.39360) | 97.34th | v4 (v2025.03.14) |
| May 15, 2026 | 41.39% (0.41386) | 97.45th | v4 (v2025.03.14) |
| Mar 28, 2026 | 48.56% (0.48556) | 97.73th | v4 (v2025.03.14) |
| Mar 14, 2026 | 53.11% (0.53106) | 97.92th | v4 (v2025.03.14) |
| Feb 20, 2026 | 61.76% (0.61763) | 98.29th | v4 (v2025.03.14) |
| Dec 21, 2025 | 63.84% (0.63842) | 98.34th | v4 (v2025.03.14) |
| Oct 6, 2025 | 69.02% (0.69016) | 98.58th | v4 (v2025.03.14) |
| Aug 8, 2025 | 61.20% (0.61195) | 98.23th | v4 (v2025.03.14) |
| Jul 16, 2025 | 58.36% (0.58360) | 98.07th | v4 (v2025.03.14) |
| Apr 13, 2025 | 60.26% (0.60264) | 98.12th | v4 (v2025.03.14) |
| Apr 6, 2025 | 69.02% (0.69016) | 98.53th | v4 (v2025.03.14) |
| Mar 29, 2025 | 70.97% (0.70966) | 98.26th | v4 (v2025.03.14) |
| Mar 28, 2025 | 73.16% (0.73158) | 98.71th | v4 (v2025.03.14) |
| Mar 19, 2025 | 70.97% (0.70966) | 98.58th | v4 (v2025.03.14) |
| Mar 18, 2025 | 63.54% (0.63536) | 98.28th | v4 (v2025.03.14) |
| Mar 17, 2025 | 66.22% (0.66216) | 98.39th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.98% (0.00977) | 84.09th | v3 (v2023.03.01) |
| May 13, 2023 | 1.91% (0.01914) | 86.81th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00054) | 19.94th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.74% (0.03744) | 85.12th | v2 (v2022.01.01) |
| Feb 13, 2023 | 3.74% (0.03744) | 84.71th | v2 (v2022.01.01) |
| Feb 3, 2023 | 5.11% (0.05106) | 89.24th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.74% (0.03744) | 83.59th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.74% (0.03744) | 66.75th | v2 (v2022.01.01) |
References (33)
- http://bugzilla.novell.com/show_bug.cgi?id=875690 x_refsource_CONFIRMIssue TrackingPermissions RequiredThird Party Advisory
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4291086b1f081b869c6d79e5b7441633dc3ace00 x_refsource_CONFIRMBroken Link
- http://linux.oracle.com/errata/ELSA-2014-0771.html x_refsource_CONFIRMThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00007.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00012.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://pastebin.com/raw.php?i=yTSFUBgZ x_refsource_MISCExploitMailing ListThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-0512.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/59218 third-party-advisoryx_refsource_SECUNIANot Applicable
- http://secunia.com/advisories/59262 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/59599 third-party-advisoryx_refsource_SECUNIABroken Link
- http://source.android.com/security/bulletin/2016-07-01.html x_refsource_CONFIRMNot Applicable
- http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15319.html x_refsource_CONFIRMThird Party Advisory
- http://www.debian.org/security/2014/dsa-2926 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.debian.org/security/2014/dsa-2928 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.exploit-db.com/exploits/33516 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2014/05/05/6 mailing-listx_refsource_MLISTMailing ListThird Party Advisory
- http://www.osvdb.org/106646 vdb-entryx_refsource_OSVDBBroken Link
- http://www.ubuntu.com/usn/USN-2196-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2197-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2198-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2199-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2200-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2201-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2202-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2203-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.ubuntu.com/usn/USN-2204-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- https://access.redhat.com/security/cve/CVE-2014-0196 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1094232 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/4291086b1f081b869c6d79e5b7441633dc3ace00 x_refsource_CONFIRMExploitPatchThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-0196
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0196 government-resourceUS Government Resource
- https://www.cve.org/CVERecord?id=CVE-2014-0196
Change history (0)
No recorded changes yet.