Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-2739

Overview

Vulnerability Score 4.6 4.6
CVE Id CVE-2014-2739
Last Modified 24 Apr 2014 01:06:26
Published 14 Apr 2014 07:55:07
Confidentiality Impact NONE NONE
Integrity Impact NONE NONE
Availability Impact COMPLETE COMPLETE
Access Vector ADJACENT_NETWORK
Access Complexity HIGH
Authentication NONE

CVE-2014-2739

Summary

The cma_req_handler function in drivers/infiniband/core/cma.c in the Linux kernel 3.14.x through 3.14.1 attempts to resolve an RDMA over Converged Ethernet (aka RoCE) address that is properly resolved within a different module, which allows remote attackers to cause a denial of service (incorrect pointer dereference and system crash) via crafted network traffic.

Vulnerable Systems

Operating System

  • Linux Kernel 3.14

  • Linux Kernel 3.14.1


References

CONFIRM - https://github.com/torvalds/linux/commit/b2853fd6c2d0f383dbdf7427e263eb576a633867

CONFIRM - https://bugzilla.redhat.com/show_bug.cgi?id=1085415

MLIST - [oss-security] 20140410 Re: CVE request Linux kernel: IB/core: crash while resolving passive side RoCE L2 address in cma_req_handler

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=b2853fd6c2d0f383dbdf7427e263eb576a633867

BID - 66716


Last Updated: 27 May 2016 11:04:56