CVE-2014-0181: Low severity Linux Linux kernel vulnerability
Last updated 24 July 2024
Other sources
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
— Launchpad
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1
Event History
Frequently Asked Questions
What is the severity of CVE-2014-0181?
CVE-2014-0181 is rated as a high severity vulnerability due to its potential to allow local users to bypass access restrictions.
How do I fix CVE-2014-0181?
To fix CVE-2014-0181, you should upgrade your Linux kernel to version 3.14.2 or later.
Which systems are affected by CVE-2014-0181?
CVE-2014-0181 affects the Linux kernel versions up to and including 3.14.1, as well as specific versions of OpenSUSE and Red Hat Enterprise Linux.
Can CVE-2014-0181 be exploited remotely?
CVE-2014-0181 requires local access to exploit, making remote exploitation impractical.
What are the consequences of CVE-2014-0181?
Exploitation of CVE-2014-0181 allows local users to modify network configurations, which could lead to further security risks.