CISA KEV · Known exploitedMedium

CVE-2014-0196

Linux Kernel

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

CVSS
5.5
EPSS
22.5%
97.5% percentile
CISA KEV
Listed
Published
2014.05.07
PRIORITY ASSESSMENT

Immediate review

CISA has listed this vulnerability in the Known Exploited Vulnerabilities catalog.

Known exploitationConfirmed by CISA KEV
Exploit probability22.5%
Technical severityCVSS 5.5

Vulnerability overview

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

Affected product and versions

Product
Linux Kernel
Affected versions
> 2.6.31 < 3.2.59, >= 3.3 < 3.4.91, >= 3.5 < 3.10.40, >= 3.11 < 3.12.20, >= 3.13 < 3.14.4, 2.6.31, 6.0, 7.0, 6.3, 6.4, 11, 6, 10.04, 12.04, 12.10, 13.10, 14.04, >= 11.1.0 <= 11.5.1, >= 11.3.0 <= 11.5.1
Fixed versions
3.2.59, 3.4.91, 3.10.40, 3.12.20, 3.14.4

Recommended response sequence

Confirm exposure before applying a vendor-supported change.

Full remediation guide
CISA required action

The impacted product is end-of-life and should be disconnected if still in use.

Due date: 2023.06.02
  1. 1
    Identify

    Confirm that Linux Kernel and an affected version are present.

  2. 2
    Prioritize

    Combine exploitation signals with asset exposure and business criticality.

  3. 3
    Remediate

    Follow the vendor advisory or supported update path and preserve rollback options.

  4. 4
    Verify

    Recheck the version, service health, access paths, and relevant logs.

Technical data

CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
CWE
CWE-362
KEV added
2023.05.12
Ransomware use
미확인