CVE-2014-0196

Confirmed PUBLISHED

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO &...

Linux · kernel
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
5.5 Medium

At a Glance

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

nessus_scanner cisa linux
CVE Published
May 07, 2014
Exploitation Reported
May 12, 2023
CVSS
5.5 Medium
EPSS
Low complexity No user interaction

Affected Versions

Vendor Product Version Status
n/a
n/a

n/a

Affected

CVE References

  • USN-2203-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-2203-1
  • SUSE-SU-2014:0683 lists.opensuse.org · Vendor Advisory http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00012...
  • USN-2204-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-2204-1
  • USN-2202-1 ubuntu.com · Vendor Advisory http://www.ubuntu.com/usn/USN-2202-1
  • DSA-2928 debian.org · Vendor Advisory http://www.debian.org/security/2014/dsa-2928
Show 23 more references

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.