CVE-2014-0196

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
Race Condition
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
redhatCNA
---
---
CVEADP
---
---
CISA-ADPADP
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 98%
VendorProductVersion
linuxlinux_kernel
2.6.31 <
𝑥
< 3.2.59
linuxlinux_kernel
3.3 ≤
𝑥
< 3.4.91
linuxlinux_kernel
3.5 ≤
𝑥
< 3.10.40
linuxlinux_kernel
3.11 ≤
𝑥
< 3.12.20
linuxlinux_kernel
3.13 ≤
𝑥
< 3.14.4
linuxlinux_kernel
2.6.31
linuxlinux_kernel
2.6.31:rc3
linuxlinux_kernel
2.6.31:rc4
linuxlinux_kernel
2.6.31:rc5
linuxlinux_kernel
2.6.31:rc6
linuxlinux_kernel
2.6.31:rc7
linuxlinux_kernel
2.6.31:rc8
linuxlinux_kernel
2.6.31:rc9
debiandebian_linux
6.0
debiandebian_linux
7.0
redhatenterprise_linux
6.0
redhatenterprise_linux_eus
6.3
redhatenterprise_linux_eus
6.4
redhatenterprise_linux_server_eus
6.3
canonicalubuntu_linux
10.04
canonicalubuntu_linux
12.04
canonicalubuntu_linux
12.10
canonicalubuntu_linux
13.10
canonicalubuntu_linux
14.04
f5big-ip_access_policy_manager
11.1.0 ≤
𝑥
≤ 11.5.1
f5big-ip_advanced_firewall_manager
11.3.0 ≤
𝑥
≤ 11.5.1
f5big-ip_analytics
11.1.0 ≤
𝑥
≤ 11.5.1
f5big-ip_application_acceleration_manager
11.4.0 ≤
𝑥
≤ 11.5.1
f5big-ip_application_security_manager
11.1.0 ≤
𝑥
≤ 11.5.1
f5big-ip_edge_gateway
11.1.0 ≤
𝑥
≤ 11.3.0
f5big-ip_global_traffic_manager
11.1.0 ≤
𝑥
≤ 11.5.1
f5big-ip_link_controller
11.1.0 ≤
𝑥
≤ 11.5.1
f5big-ip_local_traffic_manager
11.1.0 ≤
𝑥
≤ 11.5.1
f5big-ip_policy_enforcement_manager
11.3.0 ≤
𝑥
≤ 11.5.1
f5big-ip_protocol_security_module
11.1.0 ≤
𝑥
≤ 11.4.1
f5big-ip_wan_optimization_manager
11.1.0 ≤
𝑥
≤ 11.3.0
f5big-ip_webaccelerator
11.1.0 ≤
𝑥
≤ 11.3.0
f5big-iq_application_delivery_controller
4.5.0
f5big-iq_centralized_management
4.6.0
f5big-iq_cloud
4.0.0 ≤
𝑥
≤ 4.5.0
f5big-iq_cloud_and_orchestration
1.0.0
f5big-iq_device
4.2.0 ≤
𝑥
≤ 4.5.0
f5big-iq_security
4.0.0 ≤
𝑥
≤ 4.5.0
f5enterprise_manager
3.1.0
f5enterprise_manager
3.1.1
𝑥
= Vulnerable software versions
Debian logo
Debian Releases
Debian Product
Codename
linux
bullseye
5.10.223-1
fixed
bullseye (security)
5.10.226-1
fixed
bookworm
6.1.106-3
fixed
bookworm (security)
6.1.112-1
fixed
trixie
6.11.5-1
fixed
sid
6.11.6-1
fixed
Ubuntu logo
Ubuntu Releases
Ubuntu Product
Codename
linux
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
Fixed 3.13.0-24.47
released
saucy
Fixed 3.11.0-20.35
released
quantal
Fixed 3.5.0-49.74
released
precise
Fixed 3.2.0-61.93
released
lucid
Fixed 2.6.32-58.121
released
linux-armadaxp
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
ignored
precise
Fixed 3.2.0-1633.47
released
lucid
dne
linux-aws
zesty
dne
yakkety
dne
xenial
not-affected
trusty
not-affected
precise
dne
linux-ec2
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
dne
lucid
Fixed 2.6.32-363.77
released
linux-flo
zesty
dne
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
ignored
saucy
dne
quantal
dne
precise
dne
lucid
dne
linux-fsl-imx51
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
dne
lucid
ignored
linux-gke
zesty
dne
yakkety
dne
xenial
not-affected
trusty
dne
precise
dne
linux-goldfish
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
ignored
saucy
ignored
quantal
dne
precise
dne
lucid
dne
linux-grouper
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
ignored
trusty
dne
saucy
ignored
quantal
dne
precise
dne
lucid
dne
linux-hwe
zesty
dne
yakkety
dne
xenial
not-affected
trusty
dne
precise
dne
linux-hwe-edge
zesty
dne
yakkety
dne
xenial
not-affected
trusty
dne
precise
dne
linux-linaro-omap
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
ignored
precise
ignored
lucid
dne
linux-linaro-shared
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
ignored
precise
ignored
lucid
dne
linux-linaro-vexpress
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
ignored
precise
ignored
lucid
dne
linux-lts-quantal
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
Fixed 3.5.0-49.74~precise1
released
lucid
dne
linux-lts-raring
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
Fixed 3.8.0-39.58~precise1
released
lucid
dne
linux-lts-saucy
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
Fixed 3.11.0-20.35~precise1
released
lucid
dne
linux-lts-trusty
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
precise
Fixed 3.13.0-24.47~precise2
released
lucid
dne
linux-lts-utopic
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
precise
dne
lucid
dne
linux-lts-vivid
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
precise
dne
lucid
dne
linux-lts-wily
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
trusty
dne
precise
dne
linux-lts-xenial
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
trusty
not-affected
precise
dne
linux-maguro
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
ignored
quantal
dne
precise
dne
lucid
dne
linux-mako
zesty
dne
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
ignored
saucy
ignored
quantal
dne
precise
dne
lucid
dne
linux-manta
zesty
dne
yakkety
dne
xenial
dne
wily
not-affected
vivid
not-affected
utopic
not-affected
trusty
ignored
saucy
ignored
quantal
dne
precise
dne
lucid
dne
linux-mvl-dove
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
dne
precise
dne
lucid
ignored
linux-qcm-msm
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
dne
quantal
ignored
precise
ignored
lucid
ignored
linux-raspi2
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
not-affected
vivid
dne
trusty
dne
precise
dne
linux-snapdragon
zesty
not-affected
yakkety
not-affected
xenial
not-affected
wily
dne
trusty
dne
precise
dne
linux-ti-omap4
zesty
dne
yakkety
dne
xenial
dne
wily
dne
vivid
dne
utopic
dne
trusty
dne
saucy
Fixed 3.5.0-242.58
released
quantal
ignored
precise
Fixed 3.2.0-1446.65
released
lucid
dne
References