← לוח פגיעויות

CVE-2014-0196

בינונית 5.5 מנוצלת בשטח (KEV)

ניצול פעיל מאומת — קטלוג CISA KEV

שם
Linux Kernel Race Condition Vulnerability
נוסף לקטלוג
יעד טיפול (פדרלי)
פעולה נדרשת
The impacted product is end-of-life and should be disconnected if still in use.

תיאור (מקור, אנגלית)

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

מדדים

CVSS 3.1
5.5 (MEDIUM) מקור הציון: CNA CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS — סבירות ניצול
22% (אחוזון 100) נכון ל-24/7/2026
CWE
CWE-362

מוצרים מושפעים

linux: linux kernel; debian: debian linux; redhat: enterprise linux; redhat: enterprise linux eus; redhat: enterprise linux server eus; suse: suse linux enterprise desktop; suse: suse linux enterprise high availability extension; suse: suse linux enterprise server; oracle: linux; canonical: ubuntu linux; f5: big-ip access policy manager; f5: big-ip advanced firewall manager; f5: big-ip analytics; f5: big-ip application acceleration manager; f5: big-ip application security manager

קישורים