Your submission was sent successfully! Close

CVE-2014-0131

Published: 24 March 2014

Use-after-free vulnerability in the skb_segment function in net/core/skbuff.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation.

From the Ubuntu security team

Michael S. Tsirkin discovered an information leak in the Linux kernel's segmentation of skbs when using the zerocopy feature of vhost-net. A local attacker could exploit this flaw to gain potentially sensitive information from kernel memory.

Notes

AuthorNote
jdstrand
android kernels (goldfish, grouper, maguro, mako and manta) are not
supported on the Ubuntu Touch 13.10 preview kernels
apw
Also needs the following:
a5c39b046fdf5025ab4d274edaf5d8f53326b34c skbuff: skb_segment: s/fskb/list_skb/
cff87de1c2625eadcd1b38f14d3a036e160aefa3 skbuff: skb_segment: s/skb/head_skb/
ef92873b71a1879a19d64575725a7bbf8c59d9f6 skbuff: skb_segment: s/skb_frag/frag/
c4d421e6e53be12b422b5d6ff93bf6c1d6cc83d5 skbuff: skb_segment: s/frag/nskb_frag/
Priority

Medium

Status

Package Release Status
linux
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
Patches:
Introduced by

a6686f2f382b13f8a7253401a66690c3633b6a74

Fixed by 1fd819ecb90cc9b822cd84d3056ddba315d3340f
linux-armadaxp
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
This package is not directly supported by the Ubuntu Security Team
linux-aws
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-ec2
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-flo
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-fsl-imx51
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-gke
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-goldfish
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-grouper
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-hwe
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-hwe-edge
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-linaro-omap
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-linaro-shared
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-linaro-vexpress
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-lts-quantal
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-lts-raring
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-lts-saucy
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-lts-trusty
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-lts-utopic
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-lts-vivid
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-lts-wily
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-lts-xenial
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-maguro
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-mako
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-manta
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-mvl-dove
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-qcm-msm
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-raspi2
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-snapdragon
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)
linux-ti-omap4
Launchpad, Ubuntu, Debian
upstream
Released (3.14~rc7)