CVE-2014-0196 — Linux Kernel Race Condition Vulnerability
CVE-2014-0196: Linux Kernel Race Condition Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Linux |
| Product | Kernel |
| Date added | 2023-05-12 |
| Due date | 2023-06-02 |
| Ransomware campaign use | Unknown |
Description
Linux Kernel contains a race condition vulnerability within the n_tty_write function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with long strings.
Required action (CISA)
The impacted product is end-of-life and should be disconnected if still in use.
Notes
https://lkml.iu.edu/hypermail/linux/kernel/1609.1/02103.html; https://nvd.nist.gov/vuln/detail/CVE-2014-0196
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2014-0196
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog