CVE-2014-1874

Description

The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_ADMIN capability to set a zero-length security context.

Risk Information

Base Score
6.2
MODERATE
Vector
AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.075

Associated Vulnerability

VulnerabilityOS Platform
Linux kernel (USN-2133-1) linux-image-3.2.0-60-generic_3.2.0-60.91_i386.debLinux
Linux kernel (USN-2133-1) linux-image-3.2.0-60-generic_3.2.0-60.91_amd64.debLinux
Linux kernel (USN-2133-1) linux-image-3.2.0-60-virtual_3.2.0-60.91_i386.debLinux
Linux kernel (USN-2133-1) linux-image-3.2.0-60-virtual_3.2.0-60.91_amd64.debLinux
Linux kernel (USN-2133-1) linux-image-3.2.0-60-generic-pae_3.2.0-60.91_i386.debLinux
Linux hardware enablement kernel from Saucy (USN-2137-1) linux-image-3.11.0-18-generic_3.11.0-18.32~precise1_i386.debLinux
Linux hardware enablement kernel from Saucy (USN-2137-1) linux-image-3.11.0-18-generic_3.11.0-18.32~precise1_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234