cbcvebase.
CVE-2014-3917
published 2014-06-05

CVE-2014-3917: kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially…

PriorityP49low3.3CVSS 2.0
AVLACMAuNCPINAP
EPSS
0.36%
28.2th percentile
kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number.

Affected

15 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.14.7-1 (bookworm)linux 3.14.7-1 (bookworm)
linuxlinux_kernel<= 3.14.5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 3.14.7-13.14.7-1
linuxlinux_kernel>= 0 < 3.14.7-13.14.7-1
linuxlinux_kernel>= 0 < 3.14.7-13.14.7-1
linuxlinux_kernel>= 0 < 3.14.7-13.14.7-1
redhatenterprise_linux
redhatenterprise_linux
redhatenterprise_mrg
suselinux_enterprise_desktop

CVSS provenance

nvdv2.03.3LOWAV:L/AC:M/Au:N/C:P/I:N/A:P
osv3.3LOW
vendor_debian3.3LOW
vendor_redhat3.3LOW
vendor_ubuntu3.3LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.