Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2014-0069 Details

Description

The cifs_iovec_write function in fs/cifs/file.c in the Linux kernel through 3.13.5 does not properly handle uncached write operations that copy fewer than the requested number of bytes, which allows local users to obtain sensitive information from kernel memory, cause a denial of service (memory corruption and system crash), or possibly gain privileges via a writev system call with a crafted pointer.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://article.gmane.org/gmane.linux.kernel.cifs/9401 CVEBroken Link
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5d81de8e8667da7135d3a32a964087c0faf5483f CVEBroken Link
http://lists.opensuse.org/opensuse-security-announce/2014-03/msg00026.html CVEMailing ListThird Party Advisory
http://rhn.redhat.com/errata/RHSA-2014-0328.html CVEThird Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=1064253 CVEIssue TrackingThird Party Advisory

see all 16 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-119Improper Restriction of Operations within the Bounds of a Memory Buffer[email protected]

Affected Products

ProductVersions

Change History

10 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2014-0069
NVD Published Date:
Feb 28, 2014
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2014-0069 Details - Not Deferred