LOW · 2.3

CVE-2014-4027

The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitiv...

Vulnerability Description

The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator.

CVSS Score

2.3

LOW

AV:A/AC:M/Au:S/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LinuxLinux Kernel< 3.14
RedhatEnterprise Linux6.0
CanonicalUbuntu Linux12.04
SuseLinux Enterprise Desktop11
SuseLinux Enterprise High Availability Extension11
SuseLinux Enterprise Real Time Extension11
SuseLinux Enterprise Server11
F5Big-Ip Access Policy Manager>= 11.1.0, <= 11.6.0
F5Big-Ip Advanced Firewall Manager>= 11.3.0, <= 11.6.0
F5Big-Ip Analytics>= 11.1.0, <= 11.6.0
F5Big-Ip Application Acceleration Manager>= 11.4.0, <= 11.6.0
F5Big-Ip Application Security Manager>= 11.1.0, <= 11.6.0
F5Big-Ip Domain Name System12.0.0
F5Big-Ip Edge Gateway>= 11.1.0, <= 11.3.0
F5Big-Ip Global Traffic Manager>= 11.1.0, <= 11.6.0
F5Big-Ip Link Controller>= 11.1.0, <= 11.6.0
F5Big-Ip Local Traffic Manager>= 11.1.0, <= 11.6.0
F5Big-Ip Policy Enforcement Manager>= 11.3.0, <= 11.6.0
F5Big-Ip Protocol Security Module>= 11.1.0, <= 11.4.1
F5Big-Ip Wan Optimization Manager>= 11.1.0, <= 11.3.0

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-4027?

CVE-2014-4027 is a vulnerability with a CVSS score of 2.3 (LOW). The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitiv...

How severe is CVE-2014-4027?

CVE-2014-4027 has been rated LOW with a CVSS base score of 2.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-4027?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Enterprise Linux, Canonical Ubuntu Linux, Suse Linux Enterprise Desktop, Suse Linux Enterprise High Availability Extension.