Vulnerability Name: | CVE-2014-3180 (CCN-214717) | ||||||||||||||||
Assigned: | 2014-08-29 | ||||||||||||||||
Published: | 2014-08-29 | ||||||||||||||||
Updated: | 2019-11-08 | ||||||||||||||||
Summary: | ** DISPUTED ** In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_syscall uses uninitialized data when restarting compat_sys_nanosleep. Note: this is disputed because the code path is unreachable. | ||||||||||||||||
CVSS v3 Severity: | 9.1 Critical (CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H) 7.3 High (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H/E:U/RL:O/RC:U)
4.4 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N/E:U/RL:O/RC:U)
| ||||||||||||||||
CVSS v2 Severity: | 6.4 Medium (CVSS v2 Vector: AV:N/AC:L/Au:N/C:P/I:N/A:P)
| ||||||||||||||||
Vulnerability Type: | CWE-125 | ||||||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||||||
References: | Source: MITRE Type: CNA CVE-2014-3180 Source: CCN Type: Google Security Research Issue 408827 restart_syscall uses uninitialized data when restarting compat_sys_nanosleep Source: XF Type: UNKNOWN linux-kernel-cve20143180-info-disc(214717) Source: CCN Type: Linux Kernel Web site The Linux Kernel Archives | ||||||||||||||||
Vulnerable Configuration: | Configuration CCN 1: Denotes that component is vulnerable | ||||||||||||||||
Oval Definitions | |||||||||||||||||
| |||||||||||||||||
BACK |