kernel: net: ping: refcount issue in ping_init_sock() function
Published Apr 14, 2014
6.9
MEDIUMCVSS 2.0
EPSS 0.96%
Description
Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that leverages an improperly managed reference counter.
Affected products
No data.
Configuration 1
- ≥ 3.0 · < 3.2.60
- ≥ 3.3 · < 3.4.92
- ≥ 3.5 · < 3.10.41
- ≥ 3.11 · < 3.12.19
- ≥ 3.13 · < 3.14.5
- 3.0
Configuration 2
- 7.0
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-431.23.3.el6
Fixed · RHSA-2014:0981
Red Hat Enterprise Linux 6.4 Extended Update Support
kernel-0:2.6.32-358.48.1.el6
Fixed · RHSA-2014:1101
Red Hat Enterprise Linux 7
kernel-0:3.10.0-123.4.2.el7
Fixed · RHSA-2014:0786
Red Hat Enterprise MRG 2
kernel-rt-0:3.10.33-rt32.34.el6rt
Fixed · RHSA-2014:0557
Red Hat Enterprise Linux 5
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-431.23.3.el6 | Fixed | RHSA-2014:0981 |
| Red Hat Enterprise Linux 6.4 Extended Update Support | kernel-0:2.6.32-358.48.1.el6 | Fixed | RHSA-2014:1101 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-123.4.2.el7 | Fixed | RHSA-2014:0786 |
| Red Hat Enterprise MRG 2 | kernel-rt-0:3.10.33-rt32.34.el6rt | Fixed | RHSA-2014:0557 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does not affect Linux kernel packages as shipped with Red Hat Enterprise Linux 5.
References (12)
- http://secunia.com/advisories/59386 third-party-advisoryx_refsource_SECUNIABroken Link
- http://secunia.com/advisories/59599 third-party-advisoryx_refsource_SECUNIABroken Link
- http://www.debian.org/security/2014/dsa-2926 vendor-advisoryx_refsource_DEBIANThird Party Advisory
- http://www.openwall.com/lists/oss-security/2014/04/11/4 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.securityfocus.com/bid/66779 vdb-entryx_refsource_BIDThird Party AdvisoryVDB Entry
- http://www.securitytracker.com/id/1030769 vdb-entryx_refsource_SECTRACKThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2014-2851 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1086730 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=b04c46190219a4f845e46a459e3102137b7f6cac x_refsource_CONFIRMExploitPatchVendor Advisory
- https://lkml.org/lkml/2014/4/10/736 mailing-listx_refsource_MLISTMailing ListPatchVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-2851
- https://www.cve.org/CVERecord?id=CVE-2014-2851
Change history (0)
No recorded changes yet.