Vulnerability Name:

CVE-2014-2568 (CCN-91922)

Assigned:2014-03-18
Published:2014-03-18
Updated:2019-05-10
Summary:Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.
Note: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vulnerability was announced.
CVSS v3 Severity:4.0 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): None
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): Low
Integrity (I): None
Availibility (A): None
CVSS v2 Severity:2.9 Low (CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N)
2.1 Low (Temporal CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.1 Low (CCN CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N)
1.6 Low (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
2.9 Low (REDHAT CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N)
2.1 Low (REDHAT Temporal CVSS v2 Vector: AV:A/AC:M/Au:N/C:P/I:N/A:N/E:U/RL:OF/RC:C)
Exploitability Metrics:Access Vector (AV): Adjacent_Network
Access Complexity (AC): Medium
Authentication (Au): None
Impact Metrics:Confidentiality (C): Partial
Integrity (I): None
Availibility (A): None
Vulnerability Type:CWE-416
Vulnerability Consequences:Obtain Information
References:Source: MITRE
Type: CNA
CVE-2014-2568

Source: CCN
Type: RHSA-2014-0786
Important: kernel security, bug fix, and enhancement update

Source: CCN
Type: oss-security Mailing List, Thu 20 Mar 2014
CVE request -- kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied

Source: MLIST
Type: Mailing List, Third Party Advisory
[oss-sec] 20140320 CVE request -- kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied

Source: SECUNIA
Type: Broken Link
59599

Source: MLIST
Type: Mailing List, Patch, Third Party Advisory
[oss-security] 20140320 Re: CVE request -- kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied

Source: BID
Type: Third Party Advisory, VDB Entry
66348

Source: CCN
Type: BID-66348
Linux Kernel CVE-2014-2568 Information Disclosure Vulnerability

Source: UBUNTU
Type: Third Party Advisory
USN-2240-1

Source: CONFIRM
Type: Issue Tracking, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1079012

Source: XF
Type: Third Party Advisory, VDB Entry
linux-kernel-cve20142568-info-disclosure(91922)

Source: XF
Type: UNKNOWN
linux-kernel-cve20142568-info-disclosure(91922)

Source: CCN
Type: The Linux Kernel Web site
Linux Kernel

Source: MLIST
Type: Exploit, Third Party Advisory
[linux-kernel] 20140320 [PATCH v3] core, nfqueue, openvswitch: Orphan frags in skb_zerocopy and handle errors

Source: CCN
Type: WhiteSource Vulnerability Database
CVE-2014-2568

Vulnerable Configuration:Configuration 1:
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:* (Version >= 3.0 and <= 3.13.6)

  • Configuration 2:
  • cpe:/o:canonical:ubuntu_linux:14.04:*:*:*:lts:*:*:*

  • Configuration RedHat 1:
  • cpe:/o:redhat:enterprise_linux:7:*:*:*:*:*:*:*

  • Configuration RedHat 2:
  • cpe:/o:redhat:enterprise_linux:7::client:*:*:*:*:*

  • Configuration RedHat 3:
  • cpe:/o:redhat:enterprise_linux:7::computenode:*:*:*:*:*

  • Configuration RedHat 4:
  • cpe:/o:redhat:enterprise_linux:7::server:*:*:*:*:*

  • Configuration RedHat 5:
  • cpe:/o:redhat:enterprise_linux:7::workstation:*:*:*:*:*

  • Configuration CCN 1:
  • cpe:/o:linux:linux_kernel:3.14:rc7:*:*:*:*:*:*
  • AND
  • cpe:/o:redhat:enterprise_linux_hpc_node:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_desktop:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_server:7:*:*:*:*:*:*:*
  • OR cpe:/o:redhat:enterprise_linux_workstation:7:*:*:*:*:*:*:*

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:8058
    P
    perl-doc-5.26.1-150300.17.11.1 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:8036
    P
    libtdsodbc0-1.1.36-150400.12.3 on GA media (Moderate)
    2023-06-20
    oval:org.opensuse.security:def:5334
    P
    Security update for postgresql13 (Important)
    2022-08-26
    oval:org.opensuse.security:def:5309
    P
    Security update for pcre2 (Important)
    2022-07-27
    oval:org.opensuse.security:def:6058
    P
    Security update for postgresql14 (Important)
    2022-05-27
    oval:org.opensuse.security:def:20142568
    V
    CVE-2014-2568
    2022-05-20
    oval:org.opensuse.security:def:6036
    P
    Security update for tiff (Important)
    2022-05-16
    oval:org.opensuse.security:def:5234
    P
    Security update for MozillaFirefox (Important)
    2022-05-09
    oval:org.opensuse.security:def:5376
    P
    Security update for apache2 (Important)
    2022-03-21
    oval:org.opensuse.security:def:5367
    P
    Security update for libcaca (Important)
    2022-03-14
    oval:org.opensuse.security:def:5215
    P
    Security update for MozillaFirefox (Important)
    2022-01-18
    oval:org.opensuse.security:def:52034
    P
    Security update for java-1_7_1-ibm (Moderate) (in QA)
    2022-01-04
    oval:org.opensuse.security:def:7234
    P
    Security update for the Linux Kernel (Live Patch 10 for SLE 15 SP2) (Important)
    2021-12-14
    oval:org.opensuse.security:def:56106
    P
    Security update for xorg-x11-server (Important)
    2021-12-14
    oval:org.opensuse.security:def:9430
    P
    Security update for mariadb (Moderate)
    2021-12-06
    oval:org.opensuse.security:def:5153
    P
    Security update for php74 (Moderate)
    2021-11-18
    oval:org.opensuse.security:def:7215
    P
    Security update for the Linux Kernel (Live Patch 17 for SLE 15 SP2) (Important)
    2021-11-17
    oval:org.opensuse.security:def:55268
    P
    Security update for MozillaFirefox (Important)
    2021-11-17
    oval:org.opensuse.security:def:10702
    P
    Security update for the Linux Kernel (Important)
    2021-11-11
    oval:org.opensuse.security:def:9411
    P
    Security update for containerd, docker, runc (Important)
    2021-10-25
    oval:org.opensuse.security:def:9594
    P
    Security update for webkit2gtk3 (Important)
    2021-10-04
    oval:org.opensuse.security:def:5107
    P
    Security update for xerces-c (Important)
    2021-09-03
    oval:org.opensuse.security:def:9396
    P
    Security update for xen (Important)
    2021-09-03
    oval:org.opensuse.security:def:9581
    P
    Security update for mariadb (Moderate)
    2021-08-25
    oval:org.opensuse.security:def:9572
    P
    Security update for openexr (Important)
    2021-08-20
    oval:org.opensuse.security:def:7153
    P
    Security update for the Linux Kernel (Live Patch 9 for SLE 15 SP2) (Important)
    2021-08-17
    oval:org.opensuse.security:def:5085
    P
    Security update for webkit2gtk3 (Important)
    2021-08-03
    oval:org.opensuse.security:def:10687
    P
    Security update for transfig (Moderate)
    2021-07-22
    oval:org.opensuse.security:def:51928
    P
    Security update for systemd (Important)
    2021-07-21
    oval:org.opensuse.security:def:5077
    P
    Security update for systemd (Moderate)
    2021-07-20
    oval:org.opensuse.security:def:38064
    P
    Security update for OpenEXR (Important)
    2021-06-22
    oval:org.opensuse.security:def:7107
    P
    Security update for the Linux Kernel (Live Patch 4 for SLE 15 SP2) (Important)
    2021-06-18
    oval:org.opensuse.security:def:9349
    P
    Security update for apache2 (Important)
    2021-06-17
    oval:org.opensuse.security:def:9530
    P
    Security update for spice (Important)
    2021-06-11
    oval:org.opensuse.security:def:17059
    P
    kernel-default-extra-3.12.49-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11545
    P
    gnome-keyring-3.10.1-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11523
    P
    e2fsprogs-1.42.11-7.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36142
    P
    gstreamer-0_10-plugins-base-0.10.35-5.15.8 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:11566
    P
    kernel-default-3.12.49-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:76862
    P
    kernel-default-3.12.49-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36186
    P
    libfreebl3-3.17.3-0.8.11 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:13569
    P
    kernel-default-3.12.49-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:46689
    P
    kernel-default-3.12.49-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36075
    P
    PackageKit-0.3.14-2.30.11 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:15766
    P
    kernel-docs-3.12.49-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:48728
    P
    kernel-default-extra-3.12.49-11.1 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:36114
    P
    e2fsprogs-1.41.9-2.14.3 on GA media (Moderate)
    2021-06-08
    oval:org.opensuse.security:def:7085
    P
    Security update for the Linux Kernel (Live Patch 11 for SLE 15 SP2) (Important)
    2021-05-25
    oval:org.opensuse.security:def:10640
    P
    Security update for the Linux Kernel (Important)
    2021-05-12
    oval:org.opensuse.security:def:10254
    P
    Security update for java-11-openjdk (Important)
    2021-05-11
    oval:org.opensuse.security:def:7077
    P
    Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP2) (Important)
    2021-04-28
    oval:org.opensuse.security:def:55998
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP2) (Important)
    2021-04-12
    oval:org.opensuse.security:def:9303
    P
    Security update for spamassassin (Important)
    2021-04-12
    oval:org.opensuse.security:def:10232
    P
    Security update for MozillaFirefox (Important)
    2021-04-01
    oval:org.opensuse.security:def:5200
    P
    Security update for evolution-data-server (Moderate)
    2021-03-19
    oval:org.opensuse.security:def:51755
    P
    Security update for the Linux Kernel (Live Patch 33 for SLE 12 SP3) (Important)
    2021-03-17
    oval:org.opensuse.security:def:7200
    P
    Security update for the Linux Kernel (Live Patch 5 for SLE 15 SP2) (Important)
    2021-02-10
    oval:org.opensuse.security:def:9505
    P
    Security update for ImageMagick (Moderate)
    2021-01-18
    oval:org.opensuse.security:def:5398
    P
    Security update for gimp (Moderate)
    2021-01-04
    oval:org.opensuse.security:def:9281
    P
    Security update for python3 (Important)
    2020-12-23
    oval:org.opensuse.security:def:9273
    P
    Security update for xen (Important)
    2020-12-04
    oval:org.opensuse.security:def:35660
    P
    NetworkManager-gnome-0.7.1-5.22.28 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:36026
    P
    radvd-1.1-1.24.4.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35717
    P
    gzip-1.3.12-69.19.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35807
    P
    perl-libwww-perl-5.816-2.23.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35559
    P
    gpg2-2.0.9-25.25.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:35967
    P
    libpulse-browse0-0.9.23-0.7.128 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:5385
    P
    Security update for rmt-server (Important)
    2020-12-02
    oval:org.opensuse.security:def:35328
    P
    Security update for microcode_ctl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56391
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37597
    P
    libtirpc-netconfig on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38005
    P
    mipv6d on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55030
    P
    vorbis-tools on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55713
    P
    Security update for ImageMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:7385
    P
    git-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7367
    P
    emacs on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37365
    P
    xscreensaver on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52878
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15 SP1) (Important)
    2020-12-01
    oval:org.opensuse.security:def:10796
    P
    libsvn_auth_gnome_keyring-1-0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51517
    P
    Security update for dash (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52200
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:38152
    P
    cpio on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35339
    P
    Security update for mutt
    2020-12-01
    oval:org.opensuse.security:def:56198
    P
    Security update for SuSEfirewall2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37366
    P
    yast2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37698
    P
    vino on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10564
    P
    libxerces-c-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:7398
    P
    gstreamer-plugins-bad on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10863
    P
    xfsprogs-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54228
    P
    kernel-default on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52685
    P
    Security update for the Linux Kernel (Live Patch 1 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:54154
    P
    accountsservice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54867
    P
    libgnomesu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10821
    P
    mozilla-nspr-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52485
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:38180
    P
    expat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35423
    P
    Security update for openssl1 (Important)
    2020-12-01
    oval:org.opensuse.security:def:56272
    P
    Security update for gimp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37377
    P
    apache-commons-daemon on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37755
    P
    cpp48 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54868
    P
    libgraphite2-3 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55441
    P
    Security update for tcpdump (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51354
    P
    Security update for spice-vdagent (Important)
    2020-12-01
    oval:org.opensuse.security:def:7309
    P
    accountsservice on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10872
    P
    LibVNCServer-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52759
    P
    Security update for the Linux Kernel (Live Patch 12 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:36866
    P
    kernel-default on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10572
    P
    mozilla-nss-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:36824
    P
    dracut on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51355
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:52593
    P
    Security update for java-1_8_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:38224
    P
    jakarta-commons-fileupload on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:56310
    P
    Security update for samba (Important)
    2020-12-01
    oval:org.opensuse.security:def:37461
    P
    gzip on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:37845
    P
    libSoundTouch0 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:54890
    P
    libmodplug1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:55547
    P
    Security update for MozillaFirefox, mozilla-nspr, mozilla-nss (Important)
    2020-12-01
    oval:org.opensuse.security:def:7376
    P
    ft2demos on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35327
    P
    Security update for microcode_ctl (Important)
    2020-12-01
    oval:org.opensuse.security:def:7334
    P
    bzip2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10885
    P
    avahi-compat-howl-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:52797
    P
    Security update for the Linux Kernel (Live Patch 16 for SLE 15) (Important)
    2020-12-01
    oval:org.opensuse.security:def:10594
    P
    rpm-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:10721
    P
    libblkid-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38904
    P
    kernel-default-extra on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:51377
    P
    Security update for ant (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38113
    P
    DirectFB on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:38862
    P
    libmikmod3 on GA media (Moderate)
    2020-12-01
    oval:org.mitre.oval:def:27321
    P
    ELSA-2014-0786 -- kernel security, bug fix, and enhancement update (important)
    2014-12-15
    oval:org.mitre.oval:def:25261
    P
    RHSA-2014:0786: kernel security, bug fix, and enhancement update (Important)
    2014-09-08
    oval:org.mitre.oval:def:25161
    P
    USN-2260-1 -- linux-lts-trusty vulnerabilities
    2014-08-11
    oval:org.mitre.oval:def:24658
    P
    USN-2239-1 -- linux-lts-saucy vulnerabilities
    2014-07-21
    oval:org.mitre.oval:def:24753
    P
    USN-2240-1 -- linux vulnerabilities
    2014-07-21
    oval:org.mitre.oval:def:24844
    P
    USN-2241-1 -- linux vulnerabilities
    2014-07-21
    oval:com.redhat.rhsa:def:20140786
    P
    RHSA-2014:0786: kernel security, bug fix, and enhancement update (Important)
    2014-06-24
    oval:com.ubuntu.xenial:def:201425680000000
    V
    CVE-2014-2568 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-03-24
    oval:com.ubuntu.precise:def:20142568000
    V
    CVE-2014-2568 on Ubuntu 12.04 LTS (precise) - medium.
    2014-03-24
    oval:com.ubuntu.trusty:def:20142568000
    V
    CVE-2014-2568 on Ubuntu 14.04 LTS (trusty) - medium.
    2014-03-24
    oval:com.ubuntu.xenial:def:20142568000
    V
    CVE-2014-2568 on Ubuntu 16.04 LTS (xenial) - medium.
    2014-03-24
    BACK
    linux linux kernel *
    canonical ubuntu linux 14.04
    linux linux kernel 3.14 rc7
    redhat enterprise linux hpc node 7
    redhat enterprise linux desktop 7
    redhat enterprise linux server 7
    redhat enterprise linux workstation 7