Gentoo Websites Logo
Go to: Gentoo Home Documentation Forums Lists Bugs Planet Store Wiki Get Gentoo!
Bug 506432 (CVE-2014-2678) - Kernel: dereference of a NULL device in rds_iw_laddr_check (CVE-2014-2678)
Summary: Kernel: dereference of a NULL device in rds_iw_laddr_check (CVE-2014-2678)
Status: RESOLVED FIXED
Alias: CVE-2014-2678
Product: Gentoo Security
Classification: Unclassified
Component: Kernel (show other bugs)
Hardware: All Linux
: Normal normal (vote)
Assignee: Gentoo Kernel Security
URL:
Whiteboard:
Keywords:
Depends on:
Blocks:
 
Reported: 2014-04-01 10:39 UTC by Agostino Sarubbo
Modified: 2022-03-25 21:56 UTC (History)
1 user (show)

See Also:
Package list:
Runtime testing required: ---


Attachments

Note You need to log in before you can comment on or make changes to this bug.
Description Agostino Sarubbo gentoo-dev 2014-04-01 10:39:38 UTC
CVE-2014-2678 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2678):

The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through 3.14 allows local users to 
cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other 
impact via a bind system call for an RDS socket on a system that lacks RDS transports.
Comment 1 GLSAMaker/CVETool Bot gentoo-dev 2014-08-10 21:56:12 UTC
CVE-2014-2678 (http://nvd.nist.gov/nvd.cfm?cvename=CVE-2014-2678):
  The rds_iw_laddr_check function in net/rds/iw.c in the Linux kernel through
  3.14 allows local users to cause a denial of service (NULL pointer
  dereference and system crash) or possibly have unspecified other impact via
  a bind system call for an RDS socket on a system that lacks RDS transports.
Comment 2 John Helmert III archtester Gentoo Infrastructure gentoo-dev Security 2022-03-25 21:56:36 UTC
Fix in 3.15 as bf39b4247b8799935ea91d90db250ab608a58e50