CVE-2014-1444
Linux Kernel < 3.11.7 - Information Disclosure via SIOCWANDEV ioctl
Title source: llmDescription
The fst_get_iface function in drivers/net/wan/farsync.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an SIOCWANDEV ioctl call.
References (9)
Core 9
Core References
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2129-1
Vendor Advisory vendor-advisory
x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2128-1
Third Party Advisory, VDB Entry vdb-entry
x_refsource_bid
http://www.securityfocus.com/bid/64952
Third Party Advisory, VDB Entry vdb-entry
x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/90443
Patch x_refsource_confirm
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=96b340406724d87e4621284ebac5e059d67b2194
Patch mailing-list
x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/01/15/3
Patch x_refsource_confirm
https://github.com/torvalds/linux/commit/96b340406724d87e4621284ebac5e059d67b2194
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1053610
Vendor Advisory x_refsource_confirm
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.11.7
Scores
EPSS
0.0034
EPSS Percentile
26.4%
Details
CWE
CWE-399
Status
published
Products (7)
linux/linux_kernel
3.11
linux/linux_kernel
3.11.1
linux/linux_kernel
3.11.2
linux/linux_kernel
3.11.3
linux/linux_kernel
3.11.4
linux/linux_kernel
3.11.5
linux/linux_kernel
< 3.11.6
Published
Jan 18, 2014
Tracked Since
Feb 18, 2026