4
CVSSv2

CVE-2014-3940

Published: 05/06/2014 Updated: 15/07/2021
CVSS v2 Base Score: 4 | Impact Score: 6.9 | Exploitability Score: 1.9
VMScore: 357
Vector: AV:L/AC:H/Au:N/C:N/I:N/A:C

Vulnerability Summary

The Linux kernel up to and including 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.c and mm/mempolicy.c.

Vulnerable Product Search on Vulmon Subscribe to Product

redhat enterprise mrg 2.0

redhat enterprise linux 6.0

linux linux kernel 3.14

linux linux kernel 3.14.3

linux linux kernel 3.14.4

linux linux kernel

linux linux kernel 3.14.1

linux linux kernel 3.14.2

Vendor Advisories

Debian Bug report logs - #751417 linux-image-320-4-5kc-malta: no SIGKILL after prctl(PR_SET_SECCOMP, 1, ) on MIPS (CVE-2014-4157) Package: src:linux; Maintainer for src:linux is Debian Kernel Team <debian-kernel@listsdebianorg>; Reported by: Plamen Alexandrov <plamen@aomedacom> Date: Thu, 12 Jun 2014 16:21:01 ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...