CVE-2014-0181 — Kernel vulnerability
Severity
2.1LOWNVD
EPSS
0.0%
top 92.46%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedApr 27
Latest updateMay 13
Description
The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.
CVSS vector
AV:L/AC:L/C:N/I:P/A:NExploitability: 3.9 | Impact: 2.9
Affected Packages8 packages
Patches
🔴Vulnerability Details
6📋Vendor Advisories
4Debian▶
CVE-2014-0181: linux - The Netlink implementation in the Linux kernel through 3.14.1 does not provide a...↗2014