CVE-2014-7145: Null Pointer Dereference
Published Sep 28, 2014
·Updated
Last updated 24 July 2024
Other sources
The SMB2tcon function in fs/cifs/smb2pdu.c in the Linux kernel before ...
— Debian
Affected Software
10 affected componentsFixes available
redhat Enterprise Linux Desktop=7.0
redhat Enterprise Linux Hpc Node=7.0
redhat Enterprise Linux Server=7.0
redhat Enterprise Linux Workstation=7.0
Linux Linux kernel>=3.6<3.10.55
Linux Linux kernel>=3.11<3.12.29
Linux Linux kernel>=3.13<3.14.19
Linux Linux kernel>=3.15<3.16.3
Canonical Ubuntu Linux=12.04
debian/linux
5.10.223-15.10.234-16.1.129-16.1.135-16.12.25-16.12.27-1
Remediation
Event History
Sep 28, 2014
CVE Published
via MITRE·10:00 AM
Data Sourced
via MITRE·10:00 AM
Description
Jan 11, 2024
Data Sourced
via Launchpad·10:06 PM
Description
Sep 20, 2024
Data Sourced
via Ubuntu·01:05 AM
RemedyDescriptionSeverityAffected Software
Feb 27, 2025
Data Sourced
via Debian·03:14 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2014-7145?
CVE-2014-7145 is classified as a denial of service vulnerability that can lead to a client system crash caused by a NULL pointer dereference.
2
How do I fix CVE-2014-7145?
To mitigate CVE-2014-7145, it is recommended to upgrade to versions of the Linux kernel that are patched, such as 3.16.3 or later.
3
Which systems are affected by CVE-2014-7145?
CVE-2014-7145 affects various Linux kernel versions before 3.16.3 and specific distributions including Debian, Red Hat Enterprise Linux, and Ubuntu.
4
What kind of attack does CVE-2014-7145 enable?
CVE-2014-7145 enables a remote attacker to cause a denial of service through the deletion of the IPC$ share.
5
Is CVE-2014-7145 exploitable remotely?
Yes, CVE-2014-7145 can be exploited remotely by manipulating CIFS connections to induce a denial of service.