Advisory Published

USN-2140-1: Linux kernel vulnerabilities

First published: Fri Mar 07 2014(Updated: )

An information leak was discovered in the Linux kernel when built with the NetFilter Connection Tracking (NF_CONNTRACK) support for IRC protocol (NF_NAT_IRC). A remote attacker could exploit this flaw to obtain potentially sensitive kernel information when communicating over a client- to-client IRC connection(/dcc) via a NAT-ed network. (CVE-2014-1690) Matthew Thode reported a denial of service vulnerability in the Linux kernel when SELinux support is enabled. A local user with the CAP_MAC_ADMIN capability (and the SELinux mac_admin permission if running in enforcing mode) could exploit this flaw to cause a denial of service (kernel crash). (CVE-2014-1874) An information leak was discovered in the Linux kernel's NFS filesystem. A local users with write access to an NFS share could exploit this flaw to obtain potential sensative information from kernel memory. (CVE-2014-2038)

Affected SoftwareAffected VersionHow to fix
All of
ubuntu/linux-image-3.11.0-18-generic-lpae<3.11.0-18.32
3.11.0-18.32
Ubuntu gir1.2-packagekitglib-1.0=13.10
All of
ubuntu/linux-image-3.11.0-18-generic<3.11.0-18.32
3.11.0-18.32
Ubuntu gir1.2-packagekitglib-1.0=13.10

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Child vulnerabilities

(Contains the following vulnerabilities)

Frequently Asked Questions

  • What is the severity of USN-2140-1?

    The severity of USN-2140-1 is considered to be high due to its potential for information leakage.

  • How do I fix USN-2140-1?

    To fix USN-2140-1, upgrade your system to use the patched versions of the affected linux-image packages.

  • Who is affected by the vulnerability USN-2140-1?

    USN-2140-1 affects users of Ubuntu 13.10 that are running specific versions of the Linux kernel with NF_CONNTRACK support for IRC.

  • What can an attacker gain from exploiting USN-2140-1?

    An attacker leveraging USN-2140-1 could potentially access sensitive kernel information.

  • Is USN-2140-1 specific to a particular Linux version?

    Yes, USN-2140-1 specifically affects the Linux kernel version up to 3.11.0-18.32 on Ubuntu 13.10.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203