Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2014-0196 Details

Description

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2014-0196 CISA-ADPUS Government Resource
http://bugzilla.novell.com/show_bug.cgi?id=875690 CVEIssue TrackingPermissions RequiredThird Party Advisory
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4291086b1f081b869c6d79e5b7441633dc3ace00 CVEBroken Link
http://linux.oracle.com/errata/ELSA-2014-0771.html CVEThird Party Advisory
http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00007.html CVEMailing ListThird Party Advisory

see all 57 references

This CVE is in CISA's Known Exploited Vulnerabilities Catalog

Reference CISA's BOD 22-01 and Known Exploited Vulnerabilities Catalog for further guidance and requirements.

Vulnerability NameDate AddedDue DateRequired Action
Linux Kernel Race Condition VulnerabilityMay 12, 2023Jun 2, 2023The impacted product is end-of-life and should be disconnected if still in use.

Weakness Enumeration

CWE-IDCWE NameSource
CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')[email protected]
CWE-362Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')CISA-ADP

Affected Products

ProductVersions

Change History

18 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2014-0196
NVD Published Date:
May 7, 2014
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2014-0196 Details - Not Deferred