cbcvebase.
CVE-2014-2568
published 2014-03-24

CVE-2014-2568: Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain…

PriorityP411low2.9CVSS 2.0
AVAACMAuNCPINAN
EPSS
1.01%
59.9th percentile
Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. NOTE: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vulnerability was announced.

Affected

8 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debianlinux< linux 3.13.7-1 (bookworm)linux 3.13.7-1 (bookworm)
linuxlinux_kernel>= 0 < 3.13.7-13.13.7-1
linuxlinux_kernel>= 0 < 3.13.7-13.13.7-1
linuxlinux_kernel>= 0 < 3.13.7-13.13.7-1
linuxlinux_kernel>= 0 < 3.13.7-13.13.7-1
linuxlinux_kernel>= 0 < 3.13.0-29.533.13.0-29.53
linuxlinux_kernel3.0 – 3.13.6

CVSS provenance

nvdv2.02.9LOWAV:A/AC:M/Au:N/C:P/I:N/A:N
osv2.9LOW
vendor_ubuntu5.5MEDIUM
vendor_debian2.9LOW
vendor_redhat2.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.