Junglewise Threat Intelligence

CVE-2014-0196: Linux Kernel Race Condition Vulnerability

CVE-2014-0196 · Severity: critical · CVSS 6.9 · Exploited in the wild · Published 2023-05-12

Technologies: F5 Big-Ip Advanced Firewall Manager, Linux Kernel, F5 Big-Ip Access Policy Manager. Vendors: F5, Linux.

Executive brief

A race condition in the n_tty_write function in drivers/tty/n_tty.c in the Linux kernel allows local users to cause memory corruption and a system crash or gain elevated privileges. The vulnerability is triggered via specific read and write operations with long strings when the LECHO & !OPOST case is active.

Affected products

  • Linux Linux Kernel through 3.14.3
  • F5 BIG-IP Access Policy Manager 11.1.0 through 11.5.1
  • F5 BIG-IP Advanced Firewall Manager 11.3.0 through 11.5.1
  • F5 BIG-IP Analytics 11.1.0 through 11.5.1
  • F5 BIG-IP Application Acceleration Manager 11.4.0 through 11.5.1

Timeline

  • 2014-05-05: disclosed: Initial public disclosure on oss-security mailing list
  • 2023-05-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-05-12: other: Published date in advisory record

Related threats