CVE-2014-2851

medium
Published 2014-04-14 Β· Modified 2026-05-06
CVSS v3
β€”
CVSS v4 NEW
β€”
not yet in upstream
VIR risk
7.9

Description

Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that leverages an improperly managed reference counter.

Predictions

Exploit likelihood
55%
Patch ETA
β€”

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

Mitigation details

Source: Debian Security Tracker Β· View original β†— Β· DFSG

CVE-2014-2851 NameCVE-2014-2851 DescriptionInteger overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that leverages an improperly managed reference counter. SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian…

CVE-2014-2851

NameCVE-2014-2851
DescriptionInteger overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that leverages an improperly managed reference counter.
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-2926-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
linux (PTS)bullseye5.10.223-1fixed
bullseye (security)5.10.257-1fixed
bookworm6.1.170-3fixed
bookworm (security)6.1.172-1fixed
trixie6.12.86-1fixed
trixie (security)6.12.90-1fixed
forky7.0.9-1fixed
sid7.0.10-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
linuxsourcewheezy3.2.57-3+deb7u1DSA-2926-1
linuxsource(unstable)3.14.4-1low
linux-2.6source(unstable)(not affected)

Notes

- linux-2.6 <not-affected> (Introduced in 3.0)
https://lkml.org/lkml/2014/4/10/736
Upstream commit: https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=b04c46190219a4f845e46a459e3102137b7f6cac

Home - Debian Security - Source (Git)

Apply commands

text fix
Notes
- linux-2.6 <not-affected> (Introduced in 3.0)https://lkml.org/lkml/2014/4/10/736Upstream commit: https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=b04c46190219a4f845e46a459e3102137b7f6cac

Exploits

Public proof-of-concept code below. AS-IS, for defenders and authorised testing only.

Exploit-DB

EDB-32926 dos linux
Thomas Pollet Β· 2014-04-18

Linux Kernel - 'group_info' refcounter Overflow Memory Corruption

Source code queued for fetch β€” refresh in a moment.

OS impact

linux Linux kernel Affected 2 releases
VersionStatusFixed in
3.0 Affected β€”
β€” Affected 3.2.60
debian Debian Mixed 6 releases
VersionStatusFixed in
trixie Fixed 3.14.4-1
sid Fixed 3.14.4-1
forky Fixed 3.14.4-1
bullseye Fixed 3.14.4-1
bookworm Fixed 3.14.4-1
7.0 Affected β€”

References

CWEs

CWE-416

Community-verified mitigations for this CVE will appear above when contributors publish them.

Verify integrity in audit chain (admin only). AS-IS.