CVE-2014-0196: Linux Kernel Race Condition Vulnerability

Published May 1, 2014
·
Updated

It is unexpected and not allowed to call TTY buffer helpers like ttyinsertflipstring concurrently. This may lead to crashes when ECHOing is enabled and concurrect writers call ptywrite in the meantime. In that case the two writers: the ECHOing from a workqueue and ptywrite from the process race and can overflow the corresponding TTY buffer.

An unprivileged local user could use this flaw to crash the system or, potentially, escalate their privileges on the system.

References: http://seclists.org/oss-sec/2014/q2/243

Other sources

Linux Kernel contains a race condition vulnerability within the nttywrite function that allows local users to cause a denial-of-service (DoS) or gain privileges via read and write operations with long strings.

CISA

The nttywrite function in drivers/tty/ntty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

Affected Software

59 affected componentsFixes available
redhat/kernel<0:2.6.32-358.6.1.el6
0:2.6.32-358.6.1.el6
redhat/kernel<0:2.6.32-220.51.1.el6
0:2.6.32-220.51.1.el6
redhat/kernel<0:2.6.32-279.43.2.el6
0:2.6.32-279.43.2.el6
redhat/kernel<0:3.10.0-123.1.2.el7
0:3.10.0-123.1.2.el7
redhat/kernel-rt<0:3.10.33-rt32.34.el6
0:3.10.33-rt32.34.el6
Linux Kernel
Linux Linux kernel<=3.14.3
Debian Debian Linux=6.0
Debian Debian Linux=7.0
redhat Enterprise Linux=6.0
redhat Enterprise Linux Eus=6.3
redhat Enterprise Linux Eus=6.4
redhat Enterprise Linux Server Eus=6.3
SUSE SUSE Linux Enterprise Desktop=11-sp3
SUSE Suse Linux Enterprise High Availability Extension=11-sp3
SUSE SUSE Linux Enterprise Server=11-sp3
SUSE Suse Linux Enterprise Server Vmware=11-sp3
Oracle Linux=6
Canonical Ubuntu Linux=10.04
Canonical Ubuntu Linux=12.04
Canonical Ubuntu Linux=12.10
Canonical Ubuntu Linux=13.10
Canonical Ubuntu Linux=14.04
F5 BIG-IP Access Policy Manager>=11.1.0<=11.5.1
F5 BIG-IP Advanced Firewall Manager>=11.3.0<=11.5.1
F5 BIG-IP Analytics>=11.1.0<=11.5.1
F5 Big-ip Application Acceleration Manager>=11.4.0<=11.5.1
F5 BIG-IP Application Security Manager>=11.1.0<=11.5.1
F5 BIG-IP Edge Gateway>=11.1.0<=11.3.0
F5 Big-ip Global Traffic Manager>=11.1.0<=11.5.1
F5 Big-ip Link Controller>=11.1.0<=11.5.1
F5 Big-ip Local Traffic Manager>=11.1.0<=11.5.1
F5 Big-ip Policy Enforcement Manager>=11.3.0<=11.5.1
F5 Big-ip Protocol Security Module>=11.1.0<=11.4.1
F5 Big-ip Wan Optimization Manager>=11.1.0<=11.3.0
F5 Big-ip Webaccelerator>=11.1.0<=11.3.0
F5 Big-iq Application Delivery Controller=4.5.0
F5 BIG-IQ Centralized Management=4.6.0
F5 BIG-IQ Cloud>=4.0.0<=4.5.0
F5 BIG-IQ Cloud and Orchestration=1.0.0
F5 BIG-IQ Device>=4.2.0<=4.5.0
F5 BIG-IQ Security>=4.0.0<=4.5.0
F5 Enterprise Manager>=3.1.0<=3.1.1
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
Linux Linux kernel>2.6.31<3.2.59
Linux Linux kernel>=3.3<3.4.91
Linux Linux kernel>=3.5<3.10.40
Linux Linux kernel>=3.11<3.12.20
Linux Linux kernel>=3.13<3.14.4
Linux Linux kernel=2.6.31
Linux Linux kernel=2.6.31-rc3
Linux Linux kernel=2.6.31-rc4
Linux Linux kernel=2.6.31-rc5
Linux Linux kernel=2.6.31-rc6
Linux Linux kernel=2.6.31-rc7
Linux Linux kernel=2.6.31-rc8
Linux Linux kernel=2.6.31-rc9
F5 Enterprise Manager=3.1.0
F5 Enterprise Manager=3.1.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 0:2.6.32-358.6.1.el6
  2. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 0:2.6.32-220.51.1.el6
  3. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 0:2.6.32-279.43.2.el6
  4. Upgrade

    Upgrade redhat/kernel to a version that resolves this vulnerability.

    Fixed in 0:3.10.0-123.1.2.el7
  5. Upgrade

    Upgrade redhat/kernel-rt to a version that resolves this vulnerability.

    Fixed in 0:3.10.33-rt32.34.el6
  6. Upgrade

    Upgrade debian/linux to a version that resolves this vulnerability.

    Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.25-1Fixed in 6.12.27-1
  7. Compensating control

    If the impacted product/version is still in use and is end-of-life, disconnect it from the network to reduce exposure.

Event History

May 1, 2014
CVE Published
12:00 AM
May 5, 2014
Data Sourced
via Red Hat·10:38 AM
DescriptionSeverityAffected Software
May 7, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Data Sourced
via NVD·10:55 AM
RemedyDescriptionSeverityWeaknessAffected Software
May 12, 2023
Known Exploited
via CISA·12:00 AM
Jan 11, 2024
Data Sourced
via Launchpad·10:04 PM
Description
Sep 16, 2024
Data Sourced
via Ubuntu·01:03 AM
RemedyDescriptionSeverityAffected Software
Mar 1, 58274
Event
via NVD·12:57 AM

Parent advisories

This vulnerability appears in the following advisories.

Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2014-0196?

CVE-2014-0196 has been assigned a moderate severity rating due to its potential to cause crashes under specific conditions.

2

How do I fix CVE-2014-0196?

To fix CVE-2014-0196, update the kernel to versions 2.6.32-358.6.1.el6 or later, or to any fixed 3.x version as specified in vendor patches.

3

What platforms are affected by CVE-2014-0196?

CVE-2014-0196 affects various Linux kernel versions, particularly those from Red Hat, Debian, and Ubuntu distributions.

4

Can CVE-2014-0196 be exploited remotely?

CVE-2014-0196 may be exploited locally under certain conditions but is not considered to be directly exploitable remotely.

5

What symptoms might indicate an issue caused by CVE-2014-0196?

Symptoms of CVE-2014-0196 may include unexpected crashes or instability in systems utilizing concurrent writing to TTY devices.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203