CVE-2014-0196

linux kernel, debian linux, redhat enterprise linux

Published 7 May 2014 · updated 17 Jun 2026 · Analyzed

5.5 Medium · CVSS 3.1, CISA ADP

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 12 May 2023, with a remediation deadline of 2 Jun 2023 for US federal agencies.

Required action: The impacted product is end-of-life and should be disconnected if still in use.

Description

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

References