CVE-2014-7284
Summary
| CVE | CVE-2014-7284 |
|---|---|
| State | PUBLISHED |
| Assigner | mitre |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-10-13 10:55:08 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The net_get_random_once implementation in net/core/utils.c in the Linux kernel 3.13.x and 3.14.x before 3.14.5 on certain Intel processors does not perform the intended slow-path operation to initialize random seeds, which makes it easier for remote attackers to spoof or disrupt IP communication by leveraging the predictability of TCP sequence numbers, TCP and UDP port numbers, and IP ID values. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
NetworkAccess Complexity
LowAuthentication
NoneConfidentiality
NoneIntegrity
PartialAvailability
PartialAV:N/AC:L/Au:N/C:N/I:P/A:P
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | 3.13.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.13.10 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.13.11 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.13.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.13.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.13.4 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.13.5 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.13.6 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.13.7 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.13.8 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.13.9 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.14.1 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.14.2 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.14.3 | All | All | All |
| Operating System | Linux | Linux Kernel | 3.14.4 | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Second Look® | Linux Threat Detection & Response | CVE-2014-7284 NGRO Linux Kernel Bug | af854a3a-2127-422b-91ae-364da2661108 | web.archive.org | Exploit |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| oss-security - CVE Request: linux kernel net_get_random_once bug | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| net: avoid dependency of net_get_random_once on nop patching · torvalds/linux@3d44052 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | Exploit |
| www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.5 | af854a3a-2127-422b-91ae-364da2661108 | www.kernel.org | |
| Bug 1148788 – CVE-2014-7284 kernel: randomness degradation due to bug in net_get_random_once() | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.