CVE-2014-7283

Linux Kernel < 3.14.2 - Denial of Service via XFS Directory Hash Collision

Title source: llm
STIX 2.1

Description

The xfs_da3_fixhashpath function in fs/xfs/xfs_da_btree.c in the xfs implementation in the Linux kernel before 3.14.2 does not properly compare btree hash values, which allows local users to cause a denial of service (filesystem corruption, and OOPS or panic) via operations on directories that have hash collisions, as demonstrated by rmdir operations.

References (8)

Core 8
Core References
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/70261
Exploit, Patch, Third Party Advisory x_refsource_confirm
https://github.com/torvalds/linux/commit/c88547a8119e3b581318ab65e9b72f27f23e641d
Exploit, Third Party Advisory mailing-list x_refsource_mlist
http://marc.info/?l=linux-xfs&m=139590613002926&w=2
Release Notes, Vendor Advisory x_refsource_confirm
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.2
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/10/01/29
Third Party Advisory vendor-advisory x_refsource_redhat
http://rhn.redhat.com/errata/RHSA-2014-1943.html
Exploit, Issue Tracking, Patch, Third Party Advisory x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1148777

Scores

EPSS 0.0055
EPSS Percentile 42.4%

Details

CWE
CWE-399
Status published
Products (2)
linux/linux_kernel < 3.14.2
redhat/mrg_realtime 2.0
Published Oct 13, 2014
Tracked Since Feb 18, 2026