Synced 30 Sept 2026 23:45 UTC Account
← All products

CVE-2014-3145

MEDIUM severity · CVSS 4.9 · Out-of-bounds read
4.9CVSS MEDIUM

Summary

The BPF_S_ANC_NLATTR_NEST extension implementation in the sk_run_filter function in net/core/filter.c in the Linux kernel through 3.14.3 uses the reverse order in a certain subtraction, which allows local users to cause a denial of service (over-read and system crash) via crafted BPF instructions. NOTE: the affected code was moved to the __skb_get_nlattr_nest function before the vulnerability was announced.

Impact & exploitability

Attack vectorLocal
Attack complexityLow
Privileges required—
User interaction—
Confidentiality impactNone
Integrity impactNone
Availability impact—
Exploit probability (EPSS)1%

AV:L/AC:L/Au:N/C:N/I:N/A:C

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: http://www.openwall.com/lists/oss-security/2014/05/09/6 ↗