CVE-2014-3184: Buffer Overflow
Last updated 24 July 2024
Other sources
Linux kernel built with the Human Interface Device(HID) Bus support(CONFIGHID) along with a driver for
Cherry Cymotion keyboard support(CONFIGHIDCHERRY) KYE/Genius devices support(CONFIGHIDKYE) Logitech devices support(CONFIGHIDLOGITECH) Monterey Genius KB29E keyboard support(CONFIGHIDMONTEREY) Petalynx Maxter remote control support(CONFIGHIDPETALYNX) Sunplus wireless desktop support(CONFIGHIDSUNPLUS)
is vulnerable to an OOB write flaw. It could occur if an HID device report offers an invalid report descriptor size.
A local user with physical access to the system could use this flaw to write past an allocated memory buffer. This is mostly a non issue as the allocated memory buffer comes with the padding bytes used for alignment purposes.
Upstream fix: ------------- -> https://git.kernel.org/linus/4ab25786c87eb20857bbb715c3ae34ec8fd6a214
— Red Hat
The reportfixup functions in the HID subsystem in the Linux kernel before 3.16.2 might allow physically proximate attackers to cause a denial of service (out-of-bounds write) via a crafted device that provides a small report descriptor, related to (1) drivers/hid/hid-cherry.c, (2) drivers/hid/hid-kye.c, (3) drivers/hid/hid-lg.c, (4) drivers/hid/hid-monterey.c, (5) drivers/hid/hid-petalynx.c, and (6) drivers/hid/hid-sunplus.c.
— Launchpad
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3184?
CVE-2014-3184 is considered to be a medium severity vulnerability affecting the Linux kernel.
How do I fix CVE-2014-3184?
To fix CVE-2014-3184, upgrade your Linux kernel to versions 5.10.223-1, 5.10.226-1, 6.1.123-1, 6.1.128-1, 6.12.12-1, or 6.12.13-1.
Which Linux kernel versions are affected by CVE-2014-3184?
CVE-2014-3184 affects Linux kernel versions up to and including 3.16.1.
What types of devices are involved in CVE-2014-3184?
CVE-2014-3184 involves vulnerabilities related to Human Interface Devices (HID) including Cherry, KYE/Genius, and Logitech devices.
Is CVE-2014-3184 fixed in the latest Linux kernel?
Yes, CVE-2014-3184 has been addressed in newer kernel versions beyond 3.16.1.