cbcvebase.
CVE-2014-2038
published 2014-02-28

CVE-2014-2038: The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a…

PriorityP48low2.1CVSS 2.0
AVLACLAuNCPINAN
EPSS
0.41%
34.1th percentile
The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memory in opportunistic circumstances by writing to a file in an NFS filesystem and then reading the same file.

Affected

8 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 3.13.4-1 (bookworm)linux 3.13.4-1 (bookworm)
linuxlinux_kernel< 3.13.33.13.3
linuxlinux_kernel>= 0 < 3.13.4-13.13.4-1
linuxlinux_kernel>= 0 < 3.13.4-13.13.4-1
linuxlinux_kernel>= 0 < 3.13.4-13.13.4-1
linuxlinux_kernel>= 0 < 3.13.4-13.13.4-1

CVSS provenance

nvdv2.02.1LOWAV:L/AC:L/Au:N/C:P/I:N/A:N
osv2.1LOW
vendor_ubuntu2.6LOW
vendor_debian2.1LOW
vendor_redhat2.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.