CVE-2014-6418: High severity linux kernel vulnerability
A flaw was found in the kernels handling of ceph authentication tickets.
The auth reply could be returned to a client unvalidated.
Other sources
net/ceph/authx.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly validate auth replies, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via crafted data from the IP address of a Ceph Monitor.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-6418?
CVE-2014-6418 has a high severity due to the potential for remote attacks exploiting unvalidated authentication replies.
How do I fix CVE-2014-6418?
To fix CVE-2014-6418, upgrade to a kernel version that is 3.16.3 or higher, or apply the relevant patches provided by your Linux distribution.
Which software versions are affected by CVE-2014-6418?
CVE-2014-6418 affects the Linux kernel versions before 3.16.3, as well as various Ubuntu and Debian releases.
What kind of attacks can be executed due to CVE-2014-6418?
CVE-2014-6418 allows remote attackers to authenticate unvalidated client requests, leading to potential unauthorized access.
Is there a public exploit for CVE-2014-6418?
As of now, there is no widely known public exploit specifically targeting CVE-2014-6418.