Back to search
CVE-2014-2038
Published: Feb 28, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memory in opportunistic circumstances by writing to a file in an NFS filesystem and then reading the same file.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
USN-2137-1
vendor-advisory
x_refsource_UBUNTU
USN-2140-1
vendor-advisory
x_refsource_UBUNTU
[oss-security] 20140221 Re: Re: CVE request: Linux kernel: nfs: information leakage
mailing-list
x_refsource_MLIST
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.13.3
x_refsource_CONFIRM
https://bugzilla.redhat.com/show_bug.cgi?id=1066939
x_refsource_CONFIRM
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now