CVE 2014-4171
mm/shmem.c in the Linux kernel through 3.15.1 does not properly implement the interaction between range notification and hole punching, which allows local users to cause a denial of service (i_mutex hold) by using the mmap system call to access a hole, as demonstrated by interfering with intended shmem activity by blocking completion of (1) an MADV_REMOVE madvise call or (2) an FALLOC_
Related bugs and status
CVE-2014-4171 (Candidate) is related to these bugs:
Bug #1333617: CVE-2014-4171
Summary | In | Importance | Status | |||
---|---|---|---|---|---|---|
1333617 | CVE-2014-4171 | linux (Ubuntu) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-fsl-imx51 (Ubuntu) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-mvl-dove (Ubuntu) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-backport-maverick (Ubuntu) | Undecided | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-backport-natty (Ubuntu) | Undecided | Invalid | ||
1333617 | CVE-2014-4171 | linux-ti-omap4 (Ubuntu) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-ec2 (Ubuntu) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-backport-maverick (Ubuntu Utopic) | Undecided | Won't Fix | ||
1333617 | CVE-2014-4171 | linux-lts-backport-natty (Ubuntu Utopic) | Undecided | Won't Fix | ||
1333617 | CVE-2014-4171 | linux (Ubuntu Trusty) | Medium | Fix Released | ||
1333617 | CVE-2014-4171 | linux-ec2 (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-fsl-imx51 (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-backport-maverick (Ubuntu Trusty) | Undecided | Won't Fix | ||
1333617 | CVE-2014-4171 | linux-lts-backport-natty (Ubuntu Trusty) | Undecided | Won't Fix | ||
1333617 | CVE-2014-4171 | linux-mvl-dove (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-ti-omap4 (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-backport-maverick (Ubuntu Saucy) | Undecided | Won't Fix | ||
1333617 | CVE-2014-4171 | linux-lts-backport-natty (Ubuntu Saucy) | Undecided | Won't Fix | ||
1333617 | CVE-2014-4171 | linux (Ubuntu Precise) | Medium | Fix Released | ||
1333617 | CVE-2014-4171 | linux-ec2 (Ubuntu Precise) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-fsl-imx51 (Ubuntu Precise) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-backport-maverick (Ubuntu Precise) | Undecided | Won't Fix | ||
1333617 | CVE-2014-4171 | linux-lts-backport-natty (Ubuntu Precise) | Undecided | Won't Fix | ||
1333617 | CVE-2014-4171 | linux-mvl-dove (Ubuntu Precise) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-ti-omap4 (Ubuntu Precise) | Medium | Fix Released | ||
1333617 | CVE-2014-4171 | linux-lts-backport-maverick (Ubuntu Lucid) | Undecided | Won't Fix | ||
1333617 | CVE-2014-4171 | linux-lts-backport-natty (Ubuntu Lucid) | Undecided | Won't Fix | ||
1333617 | CVE-2014-4171 | linux-armadaxp (Ubuntu) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-armadaxp (Ubuntu Precise) | Medium | Fix Released | ||
1333617 | CVE-2014-4171 | linux-armadaxp (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-saucy (Ubuntu) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-saucy (Ubuntu Precise) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-saucy (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-quantal (Ubuntu) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-quantal (Ubuntu Precise) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-quantal (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-raring (Ubuntu) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-raring (Ubuntu Precise) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-raring (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux (Ubuntu Vivid) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-armadaxp (Ubuntu Vivid) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-ec2 (Ubuntu Vivid) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-fsl-imx51 (Ubuntu Vivid) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-backport-maverick (Ubuntu Vivid) | Undecided | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-backport-natty (Ubuntu Vivid) | Undecided | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-quantal (Ubuntu Vivid) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-raring (Ubuntu Vivid) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-saucy (Ubuntu Vivid) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-mvl-dove (Ubuntu Vivid) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-ti-omap4 (Ubuntu Vivid) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-trusty (Ubuntu) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-trusty (Ubuntu Precise) | Medium | Fix Released | ||
1333617 | CVE-2014-4171 | linux-lts-trusty (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-trusty (Ubuntu Vivid) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-utopic (Ubuntu) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-utopic (Ubuntu Precise) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-utopic (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-lts-utopic (Ubuntu Vivid) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-goldfish (Ubuntu) | Medium | New | ||
1333617 | CVE-2014-4171 | linux-goldfish (Ubuntu Precise) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-goldfish (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-goldfish (Ubuntu Vivid) | Medium | Won't Fix | ||
1333617 | CVE-2014-4171 | linux-flo (Ubuntu) | Medium | New | ||
1333617 | CVE-2014-4171 | linux-flo (Ubuntu Precise) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-flo (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-flo (Ubuntu Vivid) | Medium | Won't Fix | ||
1333617 | CVE-2014-4171 | linux-mako (Ubuntu) | Medium | New | ||
1333617 | CVE-2014-4171 | linux-mako (Ubuntu Precise) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-mako (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-mako (Ubuntu Vivid) | Medium | New | ||
1333617 | CVE-2014-4171 | linux-manta (Ubuntu) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-manta (Ubuntu Precise) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-manta (Ubuntu Trusty) | Medium | Invalid | ||
1333617 | CVE-2014-4171 | linux-manta (Ubuntu Vivid) | Medium | Won't Fix | ||
1333617 | CVE-2014-4171 | linux (Ubuntu Wily) | Medium | Invalid |
See the
CVE page on Mitre.org
for more details.