CVE-2014-1444
The fst_get_iface function in drivers/net/wan/farsync.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an SIOCWANDEV ioctl call.
- Affected products
- Alt Linux, Linux Kernel, Suse Linux Enterprise, Suse, Gfs2-Kmp-Xen, Kernel-Ec2-Devel, Kernel-Pae-Devel, Kernel-Xen-Devel
- Linux Linux Kernel
- ≤ 3.11.6, 3.11, 3.11.1, 3.11.2, 3.11.3, 3.11.4, 3.11.5
- Fix
- Available
- CVSS 2.0
- 1.7 LOW
- EPSS
- 0.3% (26th percentile)
- Weakness
- CWE-399
- NVD status
- Modified
- Published
- 2014-01-18
CVE-2014-1444 at NVD
1 known exploit for CVE-2014-1444
Proof-of-concept code and exploit modules indexed by Sploitus