CVE-2014-4027: Infoleak
Last updated 24 July 2024
Other sources
Linux kernel built with the Generic Target Core Mod(TCM), an iSCSI Target engine(CONFIGTARGETCORE), along with the Ramdisk back-end driver support, is vulnerable to an information leakage flaw. It could occur while performing I/O operations on behalf of a SCSI initiator.
A privileged user/process could use this flaw to leak kernel memory bytes.
Upstream fix: ------------- -> https://git.kernel.org/linus/4442dc8a92b8f9ad8ee9e7f8438f4c04c03a22dc v2-> http://permalink.gmane.org/gmane.linux.scsi.target.devel/6618
Reference: ---------- -> http://www.openwall.com/lists/oss-security/2014/06/11/1
— Red Hat
The rdbuilddevicespace function in drivers/target/targetcorerd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdiskmcp memory by leveraging access to a SCSI initiator.
— Launchpad
Affected Software
Remediation
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2014-4027?
CVE-2014-4027 has a medium severity rating due to potential information leakage during I/O operations.
How do I fix CVE-2014-4027?
To fix CVE-2014-4027, update your Linux kernel to a version that is not affected, such as those listed in the vulnerability report.
What systems are affected by CVE-2014-4027?
CVE-2014-4027 affects specific versions of Linux kernel, including Debian, Red Hat, and various SUSE distributions.
Can CVE-2014-4027 lead to data exposure?
Yes, CVE-2014-4027 can potentially lead to information leakage, which may expose sensitive data.
What types of operations are impacted by CVE-2014-4027?
CVE-2014-4027 impacts I/O operations conducted on behalf of a SCSI initiator, potentially leaking information.