CVE

Id
73717  
CVE No.
CVE-2014-6417  
Status
Candidate  
Description
net/ceph/auth_x.c in Ceph, as used in the Linux kernel before 3.16.3, does not properly consider the possibility of kmalloc failure, which allows remote attackers to cause a denial of service (system crash) or possibly have unspecified other impact via a long unencrypted auth ticket.  
Phase
Assigned (20140915)  
Votes
None (candidate not yet proposed)  
Comments