Vulnerability Intelligence Report
Linux Kernel Race Condition Vulnerability
CVE-2014-0196
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
5.5
MEDIUM
Exploitability:1.9
Impact Score:3.6
EPSS Probability:22.48%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-362 ↗CWE-362 Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| linux | linux_kernel | 2.6.31 |
| debian | debian_linux | 6.0, 7.0 |
| redhat | enterprise_linux | 6.0 |
| redhat | enterprise_linux_eus | 6.3, 6.4 |
| redhat | enterprise_linux_server_eus | 6.3 |
| suse | suse_linux_enterprise_desktop | 11 |
| suse | suse_linux_enterprise_high_availability_extension | 11 |
| suse | suse_linux_enterprise_server | 11 |
| oracle | linux | 6 |
| canonical | ubuntu_linux | 10.04, 12.04, 12.10, 13.10, 14.04 |
| f5 | big-ip_access_policy_manager | all |
| f5 | big-ip_advanced_firewall_manager | all |
| f5 | big-ip_analytics | all |
| f5 | big-ip_application_acceleration_manager | all |
| f5 | big-ip_application_security_manager | all |
| f5 | big-ip_edge_gateway | all |
| f5 | big-ip_global_traffic_manager | all |
| f5 | big-ip_link_controller | all |
| f5 | big-ip_local_traffic_manager | all |
| f5 | big-ip_policy_enforcement_manager | all |
| f5 | big-ip_protocol_security_module | all |
| f5 | big-ip_wan_optimization_manager | all |
| f5 | big-ip_webaccelerator | all |
| f5 | big-iq_application_delivery_controller | 4.5.0 |
| f5 | big-iq_centralized_management | 4.6.0 |
| f5 | big-iq_cloud | all |
| f5 | big-iq_cloud_and_orchestration | 1.0.0 |
| f5 | big-iq_device | all |
| f5 | big-iq_security | all |
| f5 | enterprise_manager | 3.1.0, 3.1.1 |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2013-12-03T00:00:00 |
| Published | 2014-05-07T10:00:00 |
| Patch Date | 2014-04-29 |
| Last Updated | 2025-10-22T00:05:37 |
Community Chatter & Buzz