Release date:
Updated on:
Affected Systems:
Linux kernel <= 3.14.3
Description:
--------------------------------------------------------------------------------
CVE (CAN) ID: CVE-2014-3145
Linux Kernel is the Kernel of the Linux operating system.
In versions earlier than Linux kernel 3.14.3, BPF_S_ANC_NLATTR_NEST is extended to net/core/filter. during the implementation of the sk_run_filter function in c, some subtraction operations use reverse order, which allows local users to use specially crafted BPF commands, this vulnerability can cause denial of service (out-of-bounds read and system crash ).
<* Source: vendor
*>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Https://github.com/torvalds/linux/commit/05ab8f2647e4221cbdb3856dd7d32bd5407316b3
Http://git.kernel.org /? P = linux/kernel/git/torvalds/linux-2.6.git; a = commit; h = 05ab8f2647e4221cbdb3856dd7d32bd5407rjb3
Http://www.openwall.com/lists/oss-security/2014/05/09/6
The Linux kernel replaces iptables with nftables
Linux 3.12 code Suicidal Squirrel
How to install Linux 3.11 Kernel on Ubuntu
The Ubuntu 13.10 (Saucy Salamander) Kernel has been upgraded to Linux Kernel 3.10 RC5
Linux Kernel 3.4.62 LTS is now available for download
How to install Linux kernel 13.10 On Ubuntu 3.12
Linux Kernel: click here
Linux Kernel: click here
This article permanently updates the link address: