SB2014090115 - Integer overflow in Linux kernel
Published: September 1, 2014
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Integer overflow (CVE-ID: CVE-2014-3601)
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to integer overflow error. A remote user can perform a denial of service (DoS) attack.
Remediation
Install update from vendor's website.
References
- https://bugzilla.redhat.com/show_bug.cgi?id=1131951
- https://github.com/torvalds/linux/commit/350b8bdd689cd2ab2c67c8a86a0be86cfa0751a7
- http://www.ubuntu.com/usn/USN-2358-1
- http://www.ubuntu.com/usn/USN-2359-1
- http://www.ubuntu.com/usn/USN-2357-1
- http://www.ubuntu.com/usn/USN-2356-1
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html
- http://www.securityfocus.com/bid/69489
- http://secunia.com/advisories/60830
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95689
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=350b8bdd689cd2ab2c67c8a86a0be86cfa0751a7