Vulnerability Name:

CVE-2017-14340 (CCN-132066)

Assigned:2017-09-13
Published:2017-09-13
Updated:2017-12-07
Summary:The XFS_IS_REALTIME_INODE macro in fs/xfs/xfs_linux.h in the Linux kernel before 4.13.2 does not verify that a filesystem has a realtime device, which allows local users to cause a denial of service (NULL pointer dereference and OOPS) via vectors related to setting an RHINHERIT flag on a directory.
CVSS v3 Severity:5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
5.5 Medium (CCN CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
4.8 Medium (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H/E:U/RL:O/RC:C)
Exploitability Metrics:Attack Vector (AV): Local
Attack Complexity (AC): Low
Privileges Required (PR): Low
User Interaction (UI): None
Scope:Scope (S): Unchanged
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): High
CVSS v2 Severity:4.9 Medium (CVSS v2 Vector: AV:L/AC:L/Au:N/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Authentication (Au): None
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
4.6 Medium (CCN CVSS v2 Vector: AV:L/AC:L/Au:S/C:N/I:N/A:C)
Exploitability Metrics:Access Vector (AV): Local
Access Complexity (AC): Low
Athentication (Au): Single_Instance
Impact Metrics:Confidentiality (C): None
Integrity (I): None
Availibility (A): Complete
Vulnerability Type:CWE-476
Vulnerability Consequences:Denial of Service
References:Source: MITRE
Type: CNA
CVE-2017-14340

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=b31ff3cdf540110da4572e3e29bd172087af65cc

Source: CONFIRM
Type: Mailing List, Mitigation, Patch, Third Party Advisory
http://seclists.org/oss-sec/2017/q3/436

Source: DEBIAN
Type: UNKNOWN
DSA-3981

Source: CONFIRM
Type: Release Notes, Vendor Advisory
http://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.2

Source: BID
Type: Third Party Advisory, VDB Entry
100851

Source: CCN
Type: BID-100851
Linux Kernel CVE-2017-14340 Local Denial of Service Vulnerability

Source: REDHAT
Type: UNKNOWN
RHSA-2017:2918

Source: CCN
Type: Red Hat Bugzilla – Bug 1491344
(CVE-2017-14340) CVE-2017-14340 kernel: xfs: unprivileged user kernel oops

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1491344

Source: XF
Type: UNKNOWN
linux-kernel-cve201714340-dos(132066)

Source: CONFIRM
Type: Issue Tracking, Patch, Third Party Advisory
https://github.com/torvalds/linux/commit/b31ff3cdf540110da4572e3e29bd172087af65cc

Source: CCN
Type: Linux Kernel Web site
The Linux Kernel Archives

Vulnerable Configuration:Configuration 1:
  • cpe:/o:linux:linux_kernel:*:*:*:*:*:*:*:* (Version <= 4.13.1)

  • * Denotes that component is vulnerable
    Oval Definitions
    Definition IDClassTitleLast Modified
    oval:org.opensuse.security:def:201714340
    V
    CVE-2017-14340
    2023-02-11
    oval:org.opensuse.security:def:30289
    P
    Security update for MozillaFirefox (Important) (in QA)
    2022-01-14
    oval:org.opensuse.security:def:31335
    P
    Security update for xorg-x11-server (Important)
    2021-12-20
    oval:org.opensuse.security:def:33038
    P
    Security update for bind (Important)
    2021-11-08
    oval:org.opensuse.security:def:35274
    P
    Security update for python (Moderate)
    2021-10-26
    oval:org.opensuse.security:def:31291
    P
    Security update for util-linux (Moderate)
    2021-10-19
    oval:org.opensuse.security:def:33985
    P
    Security update for curl (Moderate)
    2021-10-12
    oval:org.opensuse.security:def:31270
    P
    Security update for MozillaFirefox (Important)
    2021-09-22
    oval:org.opensuse.security:def:34541
    P
    Security update for gtk-vnc (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:30246
    P
    Security update for gtk-vnc (Moderate)
    2021-09-16
    oval:org.opensuse.security:def:34530
    P
    Security update for xerces-c (Important)
    2021-09-03
    oval:org.opensuse.security:def:34529
    P
    Security update for file (Important)
    2021-09-02
    oval:org.opensuse.security:def:30240
    P
    Security update for bind (Moderate)
    2021-08-30
    oval:org.opensuse.security:def:33696
    P
    Security update for mariadb (Important)
    2021-08-06
    oval:org.opensuse.security:def:31231
    P
    Security update for the Linux Kernel (Important)
    2021-07-22
    oval:org.opensuse.security:def:33690
    P
    Security update for linuxptp (Important)
    2021-07-21
    oval:org.opensuse.security:def:33928
    P
    Security update for qemu (Important)
    2021-06-10
    oval:org.opensuse.security:def:33927
    P
    Security update for caribou (Important)
    2021-06-10
    oval:org.opensuse.security:def:33922
    P
    Security update for libX11 (Important)
    2021-06-08
    oval:org.opensuse.security:def:31182
    P
    Security update for libwebp (Critical)
    2021-06-02
    oval:org.opensuse.security:def:34446
    P
    Security update for djvulibre (Important)
    2021-05-31
    oval:org.opensuse.security:def:34440
    P
    Security update for curl (Moderate)
    2021-05-26
    oval:org.opensuse.security:def:30191
    P
    Security update for cups (Important)
    2021-04-30
    oval:org.opensuse.security:def:30185
    P
    Security update for MozillaFirefox (Important)
    2021-04-27
    oval:org.opensuse.security:def:34402
    P
    Security update for spamassassin (Important)
    2021-04-12
    oval:org.opensuse.security:def:33888
    P
    Security update for fwupdate (Important)
    2021-04-08
    oval:org.opensuse.security:def:33095
    P
    Security update for python (Moderate)
    2021-03-16
    oval:org.opensuse.security:def:30038
    P
    Security update for git (Important)
    2021-03-09
    oval:org.opensuse.security:def:30032
    P
    Security update for MozillaFirefox (Important)
    2021-03-01
    oval:org.opensuse.security:def:34625
    P
    Security update for perl-File-Path (Moderate)
    2021-02-12
    oval:org.opensuse.security:def:33979
    P
    Security update for java-1_8_0-ibm (Moderate)
    2021-01-05
    oval:org.opensuse.security:def:34338
    P
    Security update for xen (Moderate)
    2020-12-18
    oval:org.opensuse.security:def:34332
    P
    Security update for curl (Moderate)
    2020-12-10
    oval:org.opensuse.security:def:29952
    P
    Security update for the Linux Kernel (Live Patch 35 for SLE 12 SP2) (Important)
    2020-12-07
    oval:org.opensuse.security:def:32011
    P
    Security update for the Linux Kernel (Live Patch 34 for SLE 12 SP3) (Important)
    2020-12-07
    oval:org.opensuse.security:def:36022
    P
    python-pam-0.5.0-3.20.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:36063
    P
    xorg-x11-libxcb-32bit-7.4-1.29.1 on GA media (Moderate)
    2020-12-03
    oval:org.opensuse.security:def:29946
    P
    Security update for python3 (Important)
    2020-12-02
    oval:org.opensuse.security:def:28410
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28063
    P
    Security update for expat (Important)
    2020-12-01
    oval:org.opensuse.security:def:28108
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:27393
    P
    empathy on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35340
    P
    Security update for mutt (Important)
    2020-12-01
    oval:org.opensuse.security:def:35124
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:32419
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30605
    P
    Security update for ruby
    2020-12-01
    oval:org.opensuse.security:def:29157
    P
    Security update for libvirt (Important)
    2020-12-01
    oval:org.opensuse.security:def:29315
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:26714
    P
    gstreamer-0_10-plugins-good on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34225
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33183
    P
    libssh2-1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31973
    P
    Security update for jakarta-taglibs-standard (Important)
    2020-12-01
    oval:org.opensuse.security:def:28421
    P
    Security update for wavpack (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28147
    P
    Security update for java-1_7_1-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:28259
    P
    Security update for lynx (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27432
    P
    libapr1 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35384
    P
    Security update for ntp (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32420
    P
    Security update for wireshark (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30737
    P
    Security update for SDL (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29201
    P
    Security update for openssl (Important)
    2020-12-01
    oval:org.opensuse.security:def:26715
    P
    gtk2 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34283
    P
    Security update for python (Important)
    2020-12-01
    oval:org.opensuse.security:def:33206
    P
    mono-core on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29585
    P
    Security update for apache2-mod_jk (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28489
    P
    Security update for curl (Important)
    2020-12-01
    oval:org.opensuse.security:def:28204
    P
    Security update for libidn (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28312
    P
    Security update for openssl (Important)
    2020-12-01
    oval:org.opensuse.security:def:27446
    P
    libgadu on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:32431
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:30827
    P
    Security update for curl (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30328
    P
    Security update for tightvnc (Important)
    2020-12-01
    oval:org.opensuse.security:def:29839
    P
    Security update for kdirstat
    2020-12-01
    oval:org.opensuse.security:def:26726
    P
    kdelibs4 on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34761
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:34074
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33250
    P
    rsync on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29586
    P
    Security update for apache2-mod_nss (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28620
    P
    Security update for xorg-x11-libXt
    2020-12-01
    oval:org.opensuse.security:def:28288
    P
    security update for mysql (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28361
    P
    Security update for postgresql94 (Important)
    2020-12-01
    oval:org.opensuse.security:def:27490
    P
    libtasn1-devel on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33595
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32509
    P
    fetchmail on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30884
    P
    Security update for MozillaFirefox
    2020-12-01
    oval:org.opensuse.security:def:30347
    P
    Security update for vim (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29875
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27681
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:26790
    P
    ofed on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34860
    P
    Security update for clamav (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34231
    P
    Security update for php5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34371
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29597
    P
    Security update for atftp (Important)
    2020-12-01
    oval:org.opensuse.security:def:28705
    P
    Security update for grub2 (Important)
    2020-12-01
    oval:org.opensuse.security:def:28440
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:28400
    P
    Security update for spice (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28128
    P
    Security update for icu (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33596
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32644
    P
    cron on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30971
    P
    Security update for gtk2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30295
    P
    Security update for squidGuard (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30391
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:27682
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:26918
    P
    ibutils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34917
    P
    Security update for emacs
    2020-12-01
    oval:org.opensuse.security:def:34289
    P
    Security update for python-imaging
    2020-12-01
    oval:org.opensuse.security:def:34396
    P
    Security update for unzip (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29591
    P
    Security update for apport (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29670
    P
    Security update for dhcp (Low)
    2020-12-01
    oval:org.opensuse.security:def:28762
    P
    Security update for libqt4
    2020-12-01
    oval:org.opensuse.security:def:28493
    P
    Security update for curl
    2020-12-01
    oval:org.opensuse.security:def:28415
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28163
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:33607
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32738
    P
    libxcrypt on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31126
    P
    Security update for kvm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30334
    P
    Security update for tomcat6 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:31029
    P
    Security update for java-1_7_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27693
    P
    Security update for xorg-x11-libxcb
    2020-12-01
    oval:org.opensuse.security:def:26999
    P
    openCryptoki on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35007
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29592
    P
    Security update for apport (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29802
    P
    Security update for inn
    2020-12-01
    oval:org.opensuse.security:def:28846
    P
    Security update for wireshark (Low)
    2020-12-01
    oval:org.opensuse.security:def:28542
    P
    Security update for pidgin
    2020-12-01
    oval:org.opensuse.security:def:28459
    P
    Security update for xfsprogs (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33601
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:32795
    P
    t1lib on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30353
    P
    Security update for w3m
    2020-12-01
    oval:org.opensuse.security:def:31066
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:27859
    P
    Security update for postgresql91 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27757
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:27056
    P
    xdg-utils on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35166
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:34377
    P
    Security update for tiff (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35078
    P
    Security update for java-1_7_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29603
    P
    Security update for axis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29889
    P
    Security update for SUSE Linux Enterprise Server 11 SP1 Kernel for Teradata (Important)
    2020-12-01
    oval:org.opensuse.security:def:28998
    P
    Security update for gnutls (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28581
    P
    Security update for LibreOffice
    2020-12-01
    oval:org.opensuse.security:def:29097
    P
    Security update for glibc (Important)
    2020-12-01
    oval:org.opensuse.security:def:33602
    P
    Security update for MozillaFirefox (Important)
    2020-12-01
    oval:org.opensuse.security:def:33826
    P
    Security update for glibc
    2020-12-01
    oval:org.opensuse.security:def:32882
    P
    hyper-v on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30397
    P
    Security update for Xen
    2020-12-01
    oval:org.opensuse.security:def:27860
    P
    Security update for ppp
    2020-12-01
    oval:org.opensuse.security:def:27885
    P
    Security update for rubygem-mail-2_3
    2020-12-01
    oval:org.opensuse.security:def:27140
    P
    gstreamer-0_10-plugins-base on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35225
    P
    Security update for liblouis (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35118
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:30519
    P
    Security update for GnuTLS
    2020-12-01
    oval:org.opensuse.security:def:29676
    P
    Security update for dnsmasq
    2020-12-01
    oval:org.opensuse.security:def:29052
    P
    Security update for bind (Critical)
    2020-12-01
    oval:org.opensuse.security:def:28597
    P
    Security update for Python
    2020-12-01
    oval:org.opensuse.security:def:29132
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:33613
    P
    Security update for xorg-x11-server (Important)
    2020-12-01
    oval:org.opensuse.security:def:31035
    P
    Security update for jpeg (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27871
    P
    Security update for python-setuptools
    2020-12-01
    oval:org.opensuse.security:def:27967
    P
    Security update for ImageMagick (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:27291
    P
    socat on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30520
    P
    Security update for gpg2
    2020-12-01
    oval:org.opensuse.security:def:29808
    P
    Security update for jakarta-commons-fileupload
    2020-12-01
    oval:org.opensuse.security:def:29101
    P
    Recommended update for glibc (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:28641
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:31072
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:28409
    P
    Security update for tidy (Low)
    2020-12-01
    oval:org.opensuse.security:def:27935
    P
    Security update for GraphicsMagick (Important)
    2020-12-01
    oval:org.opensuse.security:def:28024
    P
    Security update for bind (Important)
    2020-12-01
    oval:org.opensuse.security:def:27344
    P
    libcurl4-openssl1-32bit on GA media (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:35313
    P
    Security update for mailman (Important)
    2020-12-01
    oval:org.opensuse.security:def:35084
    P
    Security update for java-1_7_0-ibm (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:30531
    P
    Security update for java-1_6_0-ibm (Important)
    2020-12-01
    oval:org.opensuse.security:def:29895
    P
    Security update for krb5 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:29140
    P
    Security update for the Linux Kernel (Important)
    2020-12-01
    oval:org.opensuse.security:def:29279
    P
    Security update for xen (Important)
    2020-12-01
    oval:org.opensuse.security:def:33832
    P
    Security update for gnutls (Important)
    2020-12-01
    oval:org.opensuse.security:def:34068
    P
    Security update for libxml2 (Moderate)
    2020-12-01
    oval:org.opensuse.security:def:33144
    P
    libdrm on GA media (Moderate)
    2020-12-01
    oval:com.ubuntu.artful:def:201714340000
    V
    CVE-2017-14340 on Ubuntu 17.10 (artful) - medium.
    2017-09-15
    oval:com.ubuntu.bionic:def:201714340000
    V
    CVE-2017-14340 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-09-15
    oval:com.ubuntu.bionic:def:2017143400000000
    V
    CVE-2017-14340 on Ubuntu 18.04 LTS (bionic) - medium.
    2017-09-15
    oval:com.ubuntu.trusty:def:201714340000
    V
    CVE-2017-14340 on Ubuntu 14.04 LTS (trusty) - medium.
    2017-09-15
    oval:com.ubuntu.xenial:def:2017143400000000
    V
    CVE-2017-14340 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-09-15
    oval:com.ubuntu.xenial:def:201714340000
    V
    CVE-2017-14340 on Ubuntu 16.04 LTS (xenial) - medium.
    2017-09-15
    BACK
    linux linux kernel *