Lumension® Endpoint Intelligence Center

Intelligence Center » Browse All Vulnerabilities » CVE-2014-2889

Overview

Vulnerability Score 4.6 4.6
CVE Id CVE-2014-2889
Last Modified 28 Apr 2014 11:47:57
Published 26 Apr 2014 08:55:05
Confidentiality Impact PARTIAL PARTIAL
Integrity Impact PARTIAL PARTIAL
Availability Impact PARTIAL PARTIAL
Access Vector LOCAL
Access Complexity LOW
Authentication NONE

CVE-2014-2889

Summary

Off-by-one error in the bpf_jit_compile function in arch/x86/net/bpf_jit_comp.c in the Linux kernel before 3.1.8, when BPF JIT is enabled, allows local users to cause a denial of service (system crash) or possibly gain privileges via a long jump after a conditional jump.

Vulnerable Systems

Operating System

  • Linux Kernel 3.0

  • Linux Kernel 3.0.1

  • Linux Kernel 3.0.10

  • Linux Kernel 3.0.11

  • Linux Kernel 3.0.12

  • Linux Kernel 3.0.13

  • Linux Kernel 3.0.14

  • Linux Kernel 3.0.15

  • Linux Kernel 3.0.16

  • Linux Kernel 3.0.17

  • Linux Kernel 3.0.18

  • Linux Kernel 3.0.19

  • Linux Kernel 3.0.2

  • Linux Kernel 3.0.20

  • Linux Kernel 3.0.21

  • Linux Kernel 3.0.22

  • Linux Kernel 3.0.23

  • Linux Kernel 3.0.24

  • Linux Kernel 3.0.25

  • Linux Kernel 3.0.26

  • Linux Kernel 3.0.27

  • Linux Kernel 3.0.28

  • Linux Kernel 3.0.29

  • Linux Kernel 3.0.3

  • Linux Kernel 3.0.30

  • Linux Kernel 3.0.31

  • Linux Kernel 3.0.32

  • Linux Kernel 3.0.33

  • Linux Kernel 3.0.34

  • Linux Kernel 3.0.35

  • Linux Kernel 3.0.36

  • Linux Kernel 3.0.37

  • Linux Kernel 3.0.38

  • Linux Kernel 3.0.39

  • Linux Kernel 3.0.4

  • Linux Kernel 3.0.40

  • Linux Kernel 3.0.41

  • Linux Kernel 3.0.42

  • Linux Kernel 3.0.43

  • Linux Kernel 3.0.44

  • Linux Kernel 3.0.45

  • Linux Kernel 3.0.46

  • Linux Kernel 3.0.47

  • Linux Kernel 3.0.48

  • Linux Kernel 3.0.49

  • Linux Kernel 3.0.5

  • Linux Kernel 3.0.50

  • Linux Kernel 3.0.51

  • Linux Kernel 3.0.52

  • Linux Kernel 3.0.53

  • Linux Kernel 3.0.54

  • Linux Kernel 3.0.55

  • Linux Kernel 3.0.56

  • Linux Kernel 3.0.57

  • Linux Kernel 3.0.58

  • Linux Kernel 3.0.59

  • Linux Kernel 3.0.6

  • Linux Kernel 3.0.60

  • Linux Kernel 3.0.61

  • Linux Kernel 3.0.62

  • Linux Kernel 3.0.63

  • Linux Kernel 3.0.64

  • Linux Kernel 3.0.65

  • Linux Kernel 3.0.66

  • Linux Kernel 3.0.67

  • Linux Kernel 3.0.68

  • Linux Kernel 3.0.7

  • Linux Kernel 3.0.8

  • Linux Kernel 3.0.9

  • Linux Kernel 3.1

  • Linux Kernel 3.1.1

  • Linux Kernel 3.1.2

  • Linux Kernel 3.1.3

  • Linux Kernel 3.1.4

  • Linux Kernel 3.1.5

  • Linux Kernel 3.1.6

  • Linux Kernel 3.1.7


References

CONFIRM - https://github.com/torvalds/linux/commit/a03ffcf873fe0f2565386ca8ef832144c42e67fa

MLIST - [oss-security] 20140418 Re: CVE request Linux kernel: arch: x86: net: bpf_jit: an off-by-one bug in x86_64 cond jump target

CONFIRM - http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.1.8

CONFIRM - http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=a03ffcf873fe0f2565386ca8ef832144c42e67fa


Last Updated: 27 May 2016 11:05:06