Executive brief
A race condition in the n_tty_write function in drivers/tty/n_tty.c in the Linux kernel allows local users to cause memory corruption and a system crash or gain elevated privileges. The vulnerability is triggered via specific read and write operations with long strings when the LECHO & !OPOST case is active.
Affected products
- Linux Linux Kernel through 3.14.3
- F5 BIG-IP Access Policy Manager 11.1.0 through 11.5.1
- F5 BIG-IP Advanced Firewall Manager 11.3.0 through 11.5.1
- F5 BIG-IP Analytics 11.1.0 through 11.5.1
- F5 BIG-IP Application Acceleration Manager 11.4.0 through 11.5.1
Timeline
- 2014-05-05: disclosed: Initial public disclosure on oss-security mailing list
- 2023-05-12: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-05-12: other: Published date in advisory record