A buffer overflow flaw was found in the way the Minibox PicoLCD driver handled Human Interface Device (HID) reports with an invalid size. An attacker with physical access to the system could use this flaw to crash the system or, potentially, escalate their privileges on the system.
Find out more about CVE-2014-3186 from the MITRE CVE dictionary dictionary and NIST NVD.
This issue does not affect the versions of Linux kernel as shipped with
Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
This issue affects the version of the kernel package as shipped with
Red Hat Enterprise Linux 7. Future kernel updates for Red Hat Enterprise
Linux 7 may address this issue.
Base Score | 6.2 |
---|---|
Base Metrics | AV:L/AC:H/Au:N/C:C/I:C/A:C |
Access Vector | Local |
Access Complexity | High |
Authentication | None |
Confidentiality Impact | Complete |
Integrity Impact | Complete |
Availability Impact | Complete |
Find out more about Red Hat support for the Common Vulnerability Scoring System (CVSS).
Platform | Errata | Release Date |
---|---|---|
Red Hat Enterprise Linux 7 (kernel) | RHSA-2014:1971 | 2014-12-09 |
Platform | Package | State |
---|---|---|
Red Hat Enterprise MRG 2 | realtime-kernel | Not affected |
Red Hat Enterprise Linux 6 | kernel | Not affected |
Red Hat Enterprise Linux 5 | kernel | Not affected |