CVE-2014-2672: Linux Kernel

High severity, CVSS 7.1. EPSS: 2.7% chance of exploitation in the next 30 days.

Race condition in the ath_tx_aggr_sleep function in drivers/net/wireless/ath/ath9k/xmit.c in the Linux kernel before 3.13.7 allows remote attackers to cause a denial of service (system crash) via a large amount of network traffic that triggers certain list deletions.

Affected products

  • Linux Linux Kernel: from 3.2, before 3.2.56 (fixed in 3.2.56); from 3.3, before 3.4.92 (fixed in 3.4.92); from 3.5, before 3.10.42 (fixed in 3.10.42); from 3.11, before 3.12.15 (fixed in 3.12.15); from 3.13, before 3.13.7 (fixed in 3.13.7)

Published 2014-04-01. Last modified 2026-06-17.