First published: Wed Nov 06 2019(Updated: )
** DISPUTED ** In kernel/compat.c in the Linux kernel before 3.17, as used in Google Chrome OS and other products, there is a possible out-of-bounds read. restart_syscall uses uninitialized data when restarting compat_sys_nanosleep. NOTE: this is disputed because the code path is unreachable.
Credit: cve-coordination@google.com chrome-cve-admin@google.com
Affected Software | Affected Version | How to fix |
---|---|---|
Linux Kernel | <3.17 | |
Chrome OS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2014-3180 is considered potentially serious due to a possible out-of-bounds read in the Linux kernel.
To address CVE-2014-3180, upgrade your Linux kernel to version 3.17 or later.
CVE-2014-3180 affects the Linux kernel versions before 3.17 and Google Chrome OS.
CVE-2014-3180 is classified as a possible out-of-bounds read vulnerability.
The code path for CVE-2014-3180 is disputed as being unreachable, leading to further debate on its impact.