imPC@ndo IT

Tracker / CVE-2014-0181

CVE-2014-0181

Low 2.1

The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.

Affected products and versions

linux linux_kernel · … → 3.14.1
opensuse evergreen
redhat enterprise_linux_desktop
redhat enterprise_linux_server
suse linux_enterprise_real_time_extension
suse linux_enterprise_server
suse suse_linux_enterprise_server

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References