| Vulnerability Name: | CVE-2014-2889 (CCN-92684) | ||||||||||||||||||||
| Assigned: | 2014-04-15 | ||||||||||||||||||||
| Published: | 2014-04-15 | ||||||||||||||||||||
| Updated: | 2023-02-13 | ||||||||||||||||||||
| Summary: | Linux Kernel could allow a local attacker to gain elevated privileges on the system, caused by an off-by-one error in bpf_jit_comp.c. An attacker could exploit this vulnerability to gain root privileges on the system or cause the kernel to crash. | ||||||||||||||||||||
| CVSS v3 Severity: | 9.3 Critical (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
| ||||||||||||||||||||
| CVSS v2 Severity: | 4.6 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P) 3.4 Low (Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:P/I:P/A:P/E:U/RL:OF/RC:C)
5.3 Medium (CCN Temporal CVSS v2 Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C/E:U/RL:OF/RC:C)
| ||||||||||||||||||||
| Vulnerability Consequences: | Gain Privileges | ||||||||||||||||||||
| References: | Source: MITRE Type: CNA CVE-2014-2889 Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: oss-security Mailing List, Tue 15 Apr 2014 CVE request Linux kernel: arch: x86: net: bpf_jit: an off-by-one bug in x86_64 cond jump target Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com Source: CCN Type: BID-66931 Linux Kernel 'bpf_jit_compile()' Function Denial of Service Vulnerability Source: XF Type: UNKNOWN linux-kernel-cve20142889-priv-esc(92684) Source: CCN Type: Linux Kernel GIT Repository net: bpf_jit: fix an off-one bug in x86_64 cond jump target Source: secalert@redhat.com Type: UNKNOWN secalert@redhat.com | ||||||||||||||||||||
| Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||||||
| Oval Definitions | |||||||||||||||||||||
| |||||||||||||||||||||
| BACK | |||||||||||||||||||||