cbcvebase.
CVE-2014-3940
published 2014-06-05

CVE-2014-3940: The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory…

PriorityP414medium4CVSS 2.0
AVLACHAuNCNINAC
EPSS
0.27%
19.3th percentile
The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.c and mm/mempolicy.c.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.14.7-1 (bookworm)linux 3.14.7-1 (bookworm)
linuxlinux_kernel<= 3.14.5
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 3.14.7-13.14.7-1
linuxlinux_kernel>= 0 < 3.14.7-13.14.7-1
linuxlinux_kernel>= 0 < 3.14.7-13.14.7-1
linuxlinux_kernel>= 0 < 3.14.7-13.14.7-1
linuxlinux_kernel>= 0 < 3.13.0-32.573.13.0-32.57
redhatenterprise_linux
redhatenterprise_mrg

CVSS provenance

nvdv2.04.0MEDIUMAV:L/AC:H/Au:N/C:N/I:N/A:C
osv4.0MEDIUM
vendor_debian4.0LOW
vendor_redhat4.0MEDIUM
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.