CVE-2014-6416: Buffer Overflow
A buffer overflow is present in the method that the kernel uses to handle libceph auth tokens.
Other sources
Buffer overflow in net/ceph/authx.c in Ceph, as used in the Linux kernel before 3.16.3, allows remote attackers to cause a denial of service (memory corruption and panic) or possibly have unspecified other impact via a long unencrypted auth ticket.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6416?
CVE-2014-6416 is considered a high-severity vulnerability due to its potential to cause a denial of service and memory corruption.
How do I fix CVE-2014-6416?
To fix CVE-2014-6416, upgrade to a patched version of the Linux kernel that is above 3.16.3 or apply the relevant security updates provided by your distribution.
Which Linux versions are affected by CVE-2014-6416?
CVE-2014-6416 affects various versions of the Linux kernel prior to 3.16.3 and specific Ubuntu versions like 12.04 and 14.04.
Can CVE-2014-6416 be exploited remotely?
Yes, CVE-2014-6416 can be exploited remotely, allowing attackers to potentially cause a denial of service.
What components are involved in CVE-2014-6416?
CVE-2014-6416 involves a buffer overflow vulnerability in the ceph auth tokens handling in the Linux kernel.