CVE-2018-14634
published 2018-09-25CVE-2018-14634: An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged)…
PriorityP183high7.8CVSS 3.0
AVLACLPRLUINSUCHIHAH
KEVITWEXPLOIT
CISA Known Exploited Vulnerabilitydue 2026-02-16
Exploited in the wild
EPSS
14.81%
96.3th percentile
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
Affected
104 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| canonical | ubuntu_linux | — | — |
| canonical | ubuntu_linux | — | — |
| debian | linux | < linux 4.12.6-1 (bookworm) | linux 4.12.6-1 (bookworm) |
| f5 | big-ip_access_policy_manager | >= 11.2.1 < 11.6.4 | 11.6.4 |
| f5 | big-ip_access_policy_manager | >= 12.1.0 < 12.1.5 | 12.1.5 |
| f5 | big-ip_access_policy_manager | >= 13.0.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_access_policy_manager | >= 14.0.0 < 14.0.1.1 | 14.0.1.1 |
| f5 | big-ip_access_policy_manager | >= 14.1.0 < 14.1.0.6 | 14.1.0.6 |
| f5 | big-ip_advanced_firewall_manager | >= 11.2.1 < 11.6.4 | 11.6.4 |
| f5 | big-ip_advanced_firewall_manager | >= 12.1.0 < 12.1.5 | 12.1.5 |
| f5 | big-ip_advanced_firewall_manager | >= 13.0.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_advanced_firewall_manager | >= 14.0.0 < 14.0.1.1 | 14.0.1.1 |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.0 < 14.1.0.6 | 14.1.0.6 |
| f5 | big-ip_analytics | >= 11.2.1 < 11.6.4 | 11.6.4 |
| f5 | big-ip_analytics | >= 12.1.0 < 12.1.5 | 12.1.5 |
| f5 | big-ip_analytics | >= 13.0.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_analytics | >= 14.0.0 < 14.0.1.1 | 14.0.1.1 |
| f5 | big-ip_analytics | >= 14.1.0 < 14.1.0.6 | 14.1.0.6 |
| f5 | big-ip_application_acceleration_manager | >= 11.2.1 < 11.6.4 | 11.6.4 |
| f5 | big-ip_application_acceleration_manager | >= 12.1.0 < 12.1.5 | 12.1.5 |
| f5 | big-ip_application_acceleration_manager | >= 13.0.0 < 13.1.1.5 | 13.1.1.5 |
| f5 | big-ip_application_acceleration_manager | >= 14.0.0 < 14.0.1.1 | 14.0.1.1 |
| f5 | big-ip_application_acceleration_manager | >= 14.1.0 < 14.1.0.6 | 14.1.0.6 |
| f5 | big-ip_application_security_manager | >= 11.2.1 < 11.6.4 | 11.6.4 |
| f5 | big-ip_application_security_manager | >= 12.1.0 < 12.1.5 | 12.1.5 |
Detection & IOCsextracted from sources · hover to see the quote
- →The exploit targets 64-bit systems only; privilege escalation via a SUID-root binary exploiting an integer overflow in create_elf_tables(). Monitor for unprivileged users executing SUID binaries with abnormally large argument/environment vectors. ↗
- →Exploitation requires the system to have at least 32GB of RAM; systems below this threshold are unlikely to be successfully exploited due to memory demands during exploitation. ↗
- →The vulnerability is triggered during ELF binary loading; monitor for processes attempting to map extremely large argument/environment arrays (approaching MAX_ARG_STRINGS or MAX_ARG_STRLEN limits) when executing SUID binaries. ↗
- →Vulnerable kernel versions are 2.6.x, 3.10.x, and 4.14.x; patch status should be verified against these branches. The flaw is known as 'Mutagen Astronomy'. ↗
- ·Exploitation is only feasible on 64-bit systems; 32-bit systems are not affected by this integer overflow in create_elf_tables(). ↗
- ·Systems with less than 32GB of RAM are practically protected from exploitation due to the memory requirements of the attack. ↗
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vulncheck7.8HIGH
cisa7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.0HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-4994-8w6g-9jvw: An integer overflow flaw was found in the Linux kernel's create_elf_tables() function
ghsa_unreviewed·2022-05-13
CVE-2018-14634 [HIGH] CWE-190 GHSA-4994-8w6g-9jvw: An integer overflow flaw was found in the Linux kernel's create_elf_tables() function
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
OSV
linux vulnerabilities
osv·2018-10-01·CVSS 7.0
CVE-2018-15594 [HIGH] linux vulnerabilities
linux vulnerabilities
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing speculative execution and
prediction of return addresses via Return Stack Buffer (RSB) may allow
unauthorized memory reads via sidechannel attacks. An attacker could use
this to expose sensitive information. (CVE-2018-15572)
It was discovered that an integer overflow vulnerability existed in the
Linux kernel when loading an executable to run. A local attacker could use
this to gain administrative privileges. (CVE-2018-14634)
It was disc
OSV
CVE-2018-14634: An integer overflow flaw was found in the Linux kernel's create_elf_tables() function
osv·2018-09-25·CVSS 7.8
CVE-2018-14634 [HIGH] CVE-2018-14634: An integer overflow flaw was found in the Linux kernel's create_elf_tables() function
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
VulnCheck
Linux Kernel Integer Overflow Vulnerability
vulncheck·2018·CVSS 7.8
CVE-2018-14634 [HIGH] CWE-190 Linux Kernel Integer Overflow Vulnerability
Linux Kernel Integer Overflow Vulnerability
Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system.
Affected: Linux Kernel
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://www.recordedfuture.com/blog/january-2026-cve-landscape
Exploit PoC: https://vulncheck.com/xdb/30f200b5310a
Remediation Due: 2026-02-16
CISA
Linux Kernel Integer Overflow Vulnerability
cisa·2026-01-26·CVSS 7.8
CVE-2018-14634 [HIGH] CWE-190 Linux Kernel Integer Overflow Vulnerability
Vulnerability: Linux Kernel Integer Overflow Vulnerability
Affected: Linux Kernel
Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system.
Required Action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Notes: This vulnerability affects a common open-source component, third-party library, or a protocol used by different products. Please check with specific vendors for information on patching status. For more information, please see: https://git.kernel.org/pub/scm/linux/kernel/git/stable/linux.git
Palo Alto
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
vendor_paloalto·2025-02-12·CVSS 7.1
CVE-2015-5312 [HIGH] PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
PAN-SA-2025-0006 Informational Bulletin: Impact of OSS CVEs in PAN-OS
T he Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS software. While PAN-OS software may include the
CVEs: CVE-2015-5312, CVE-2016-4607, CVE-2016-4608, CVE-2016-4609, CVE-2016-4738, CVE-2018-1111, CVE-2018-14634, CVE-2018-18653, CVE-2019-0145, CVE-2019-8331, CVE-2020-0599, CVE-2020-14343, CVE-2020-14779, CVE-2020-27844, CVE-2020-29569, CVE-2021-21315, CVE-2021-27853, CVE-2021-27854, CVE-2021-27861, CVE-2021-27862, CVE-2021-3618, CVE-2021-3711, CVE-2022-2097, CVE-2022-22816, CVE-2022-40303, CVE-2022-41723, CVE-2022-41741, CVE-2022-41742, CVE-2023-3247, CVE-2023-38408, CVE-2023-44466, CVE-2023-50781, CVE-2023-50782, CVE-2024-12084, CV
Palo Alto
Privilege Escalation in PAN-OS
vendor_paloalto·2019-03-20·CVSS 7.8
CVE-2018-14634 [HIGH] CWE-190 Privilege Escalation in PAN-OS
Privilege Escalation in PAN-OS
Palo Alto Networks is aware of an integer overflow vulnerability in the Linux kernel's create_elf_tables() function. (Ref # PAN-105966, CVE-2018-14634)
Successful exploitation of this issue may allow an unprivileged local user to escalate their privileges on the system.
To successfully exploit this vulnerability, an attacker would need local user account to access CLI, as well as, an unrelated vulnerability allowing the local user to execute arbitrary code in a chained attack. This combination would result in the execution of malicious code and achieving complete control of the affected system.
This issue does not affect 32-bit systems as they do not have a large enough address space to exploit this flaw.
This issue affects This only affects 64bit systems
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-10-02·CVSS 7.0
CVE-2018-14633 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that an integer overflow vulnerability existed in the
Linux kernel when loading an executable to run. A local attacker could use
this to gain administrative privileges. (CVE-2018-14634)
It was discovered that a stack-based buffer overflow existed in the iSCSI
target implementation of the Linux kernel. A remote attacker could use this
to cause a denial of service (system crash). (CVE-2018-14633)
Instructions: After a standard system update you need to reboot your computer to make
all the necessary changes.
ATTENTION: Due to an unavoidable ABI change the kernel updates have
been given a new version number, which requires you to recompile and
reinstall all third party ke
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2018-10-01·CVSS 7.0
CVE-2018-14633 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3775-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing speculative execution and
prediction of return addresses via Return Stack Buffer (RSB) may allow
unauthorized memory reads via sidechan
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2018-10-01·CVSS 7.0
CVE-2018-14633 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the paravirtualization implementation in the Linux
kernel did not properly handle some indirect calls, reducing the
effectiveness of Spectre v2 mitigations for paravirtual guests. A local
attacker could use this to expose sensitive information. (CVE-2018-15594)
It was discovered that microprocessors utilizing speculative execution and
prediction of return addresses via Return Stack Buffer (RSB) may allow
unauthorized memory reads via sidechannel attacks. An attacker could use
this to expose sensitive information. (CVE-2018-15572)
It was discovered that an integer overflow vulnerability existed in the
Linux kernel when loading an executable to run. A local attacker
Red Hat
kernel: Integer overflow in Linux's create_elf_tables function
vendor_redhat·2018-09-25·CVSS 7.8
CVE-2018-14634 [HIGH] CWE-190 kernel: Integer overflow in Linux's create_elf_tables function
kernel: Integer overflow in Linux's create_elf_tables function
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system.
Statement: This issue does not affect 32-bit systems as they do not have a large enough address space to exploit this flaw.
Systems with less than 32GB of memory are very unlikely to be affected by th
Debian
CVE-2018-14634: linux - An integer overflow flaw was found in the Linux kernel's create_elf_tables() fun...
vendor_debian·2018·CVSS 7.8
CVE-2018-14634 [HIGH] CVE-2018-14634: linux - An integer overflow flaw was found in the Linux kernel's create_elf_tables() fun...
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
Scope: local
bookworm: resolved (fixed in 4.12.6-1)
bullseye: resolved (fixed in 4.12.6-1)
forky: resolved (fixed in 4.12.6-1)
sid: resolved (fixed in 4.12.6-1)
trixie: resolved (fixed in 4.12.6-1)
No detection rules found.
Qualys
Mutagen Astronomy: From Discovery to CISA Recognition—A Seven-Year Journey
blogs_qualys·2026-02-02·CVSS 7.8
CVE-2018-14634 [HIGH] Mutagen Astronomy: From Discovery to CISA Recognition—A Seven-Year Journey
## Table of Contents
Introduction
Why This Matters Now
Looking Back: The Original Discovery
Guidance for Security Teams
A Note on Our Research Mission
Conclusion
Frequently Asked Questions (FAQs)
## Introduction
On January 26, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2018-14634 to its Known Exploited Vulnerabilities (KEV) catalog . The same vulnerability was discovered by the Qualys Threat Research Unit (TRU) in September 2018.
We nicknamed it “Mutagen Astronomy” as a tribute to the 1992 film Sneakers . In that movie, the phrase “Setec Astronomy” is revealed as an anagram for “Too Many Secrets.” Following that tradition, “Mutagen Astronomy” is our anagram for “Too Many Arguments”, which precisely captures the technical root cause of this vulnera
Qualys
Mutagen Astronomy: A Linux Vulnerability’s Path to CISA KEV | Qualys
blogs_qualys·2026-02-02·CVSS 7.8
CVE-2018-14634 [HIGH] Mutagen Astronomy: A Linux Vulnerability’s Path to CISA KEV | Qualys
#### Table of Contents
- Introduction
- Why This Matters Now
- Looking Back: The Original Discovery
- Guidance for Security Teams
- A Note on Our Research Mission
- Conclusion
- Frequently Asked Questions (FAQs)
## Introduction
On January 26, 2026, the Cybersecurity and Infrastructure Security Agency (CISA) added CVE-2018-14634 to its Known Exploited Vulnerabilities (KEV) catalog. The same vulnerability was discovered by the Qualys Threat Research Unit (TRU) in September 2018.
We nicknamed it “Mutagen Astronomy” as a tribute to the 1992 film Sneakers. In that movie, the phrase “Setec Astronomy” is revealed as an anagram for “Too Many Secrets.” Following that tradition, “Mutagen Astronomy” is our anagram for “Too Many Arguments”, which precisely captures the technical root cause of this
Qualys
Hackers Exploit Facebook Bug, As Twitter DMs (Maybe) Got Misrouted
blogs_qualys·2018-10-02
Hackers Exploit Facebook Bug, As Twitter DMs (Maybe) Got Misrouted
In our latest security news digest, we check out the Facebook hack heard ’round the world, a Twitter bug that rattled users but may not amount to much, and a pair of serious Linux kernel vulnerabilities.
## Facebook scrambles to investigate major breach affecting tens of millions of users
The cyber security world shook on Friday upon learning that attackers exploited a software flaw on Facebook that allowed them to obtain access tokens for 50 million accounts, with another 40 million accounts possibly also affected.
Equally or even more concerning: The purloined tokens could have been used to access accounts in other websites into which their users log in with their Facebook credentials, such as Spotify and AirBnB.
Facebook inadvertently introduced the bug in July of last year. After i
Qualys
Hackers Exploit Facebook Bug, As Twitter DMs (Maybe) Got Misrouted | Qualys
blogs_qualys·2018-10-02
Hackers Exploit Facebook Bug, As Twitter DMs (Maybe) Got Misrouted | Qualys
In our latest security news digest, we check out the Facebook hack heard ’round the world, a Twitter bug that rattled users but may not amount to much, and a pair of serious Linux kernel vulnerabilities.
### Facebook scrambles to investigate major breach affecting tens of millions of users
The cyber security world shook on Friday upon learning that attackers exploited a software flaw on Facebook that allowed them to obtain access tokens for 50 million accounts, with another 40 million accounts possibly also affected.
Equally or even more concerning: The purloined tokens could have been used to access accounts in other websites into which their users log in with their Facebook credentials, such as Spotify and AirBnB.
Facebook inadvertently introduced the bug in July of last year. After
Recorded Future
January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
blogs_recorded_future·CVSS 4.9
[MEDIUM] January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
# January 2026 CVE Landscape: 23 Critical Vulnerabilities Mark 5% Increase, APT28 Exploits Microsoft Office Zero-Day
January 2026 saw a modest 5% increase in high-impact vulnerabilities, with Recorded Future's Insikt Group® identifying 23 vulnerabilities requiring immediate remediation, up from 22 in December 2025. Noteworthy trends last month included Russian state-sponsored exploitation of a Microsoft Office zero-day and critical authentication bypass flaws affecting enterprise infrastructure.
What security teams need to know:
- APT28's Operation Neusploit: Russian state-sponsored actors exploited CVE-2026-21509 (Microsoft Office) via weaponized RTF files, delivering MiniDoor, PixyNetLoader, and Covenant Grunt implants
- Microsoft and SmarterTools lead concerns: These vendors accounte
Bugzilla
CVE-2018-14634 kernel: Integer overflow in Linux's create_elf_tables function
bugzilla·2018-08-31·CVSS 7.8
CVE-2018-14634 [HIGH] CVE-2018-14634 kernel: Integer overflow in Linux's create_elf_tables function
CVE-2018-14634 kernel: Integer overflow in Linux's create_elf_tables function
A flaw was found in the Linux kernels with commit b6a2fea39318 ("mm: variable length argument support", from July 19, 2007) but without commit da029c11e6b1 ("exec:Limit arg stack to at most 75% of _STK_LIM", from July 7, 2017). An integer overflow in the Linux kernel's create_elf_tables() function. A local attacker can exploit this vulnerability via a SUID-root binary and obtain full root privileges.
Referenced commits:
b6a2fea39318 ("mm: variable length argument support", from July 19, 2007)
https://github.com/torvalds/linux/commit/b6a2fea39318e43fee84fa7b0b90d68bed92d2ba
da029c11e6b1 ("exec: Limit arg stack to at most 75% of _STK_LIM", from July 7, 2017)
https://github.com/torvalds/linux/commit/da029c11e6b1
Bugzilla
CVE-2018-5391 kernel: IP fragments with random offsets allow a remote denial of service (FragmentSmack)
bugzilla·2018-07-30·CVSS 7.5
CVE-2018-5391 [HIGH] CVE-2018-5391 kernel: IP fragments with random offsets allow a remote denial of service (FragmentSmack)
CVE-2018-5391 kernel: IP fragments with random offsets allow a remote denial of service (FragmentSmack)
A flaw named FragmentSmack was found in the way the Linux kernel handled reassembly of fragmented IPv4 and IPv6 packets. A remote attacker could use this flaw to trigger time and calculation expensive fragment reassembly algorithms by sending specially crafted packets which could lead to a CPU saturation and hence a denial of service on the system.
External References:
https://access.redhat.com/articles/3553061
https://www.kb.cert.org/vuls/id/641765
A fix is a merge commit in the Linux kernel tree:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=c30f1fc041b74ecdb072dd44f858750414b8b19f
consisting of the following commits:
7969e5c40dfd04799d4341f1b7cd
arXiv
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
arxiv_fulltext·2022-09-26
Timeloops: Automatic System Call Policy Learning for Containerized Microservices
Meghna Pancholi
[email protected]
Columbia University
Andreas D. Kellas
[email protected]
Columbia University
Vasileios P. Kemerlis
[email protected]
Brown University
Simha Sethumadhavan
[email protected]
Columbia University
## Abstract
We introduce , a novel technique for automatically learning system
call filtering policies for containerized microservices applications. At
run-time, automatically learns which system calls a program should
be allowed to invoke, while rejecting attempts to call spurious system calls.
Further, addresses many of the shortcomings of state-of-the-art
static analysis-based techniques, such as the ability to generate tight filters
for programs written in interpreted languages such as PHP, Python, and
JavaScript. has a simple and rob
arXiv
Adelie: Continuous Address Space Layout Re-randomization for Linux Drivers
arxiv_fulltext·2022-01-20
Adelie: Continuous Address Space Layout Re-randomization for Linux Drivers
[Adelie: Continuous Address Space Layout Re-randomization for Linux Drivers]Adelie: Continuous Address Space Layout Re-randomization for Linux Drivers
The U.S. Government is authorized to reproduce and distribute reprints for Governmental purposes notwithstanding any copyright annotation thereon.
Ruslan Nikolaev
Most of the work was done while the author worked at Virginia Tech.
[email protected]
The Pennsylvania State University
University Park
PA
USA
Hassan Nadeem
[email protected]
Virginia Tech
Blacksburg
VA
USA
Cathlyn Stone
[email protected]
Virginia Tech
Blacksburg
VA
USA
Binoy Ravindran
[email protected]
Virginia Tech
Blacksburg
VA
USA
## Abstract
While address space layout randomization (ASLR) has been extensively studied for user-space programs, the corresponding OS kernel's KASLR s
http://www.openwall.com/lists/oss-security/2021/07/20/2http://www.securityfocus.com/bid/105407https://access.redhat.com/errata/RHSA-2018:2748https://access.redhat.com/errata/RHSA-2018:2763https://access.redhat.com/errata/RHSA-2018:2846https://access.redhat.com/errata/RHSA-2018:2924https://access.redhat.com/errata/RHSA-2018:2925https://access.redhat.com/errata/RHSA-2018:2933https://access.redhat.com/errata/RHSA-2018:3540https://access.redhat.com/errata/RHSA-2018:3586https://access.redhat.com/errata/RHSA-2018:3590https://access.redhat.com/errata/RHSA-2018:3591https://access.redhat.com/errata/RHSA-2018:3643https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14634https://security.netapp.com/advisory/ntap-20190204-0002/https://security.paloaltonetworks.com/CVE-2018-14634https://support.f5.com/csp/article/K20934447?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/3775-1/https://usn.ubuntu.com/3775-2/https://usn.ubuntu.com/3779-1/https://www.exploit-db.com/exploits/45516/https://www.openwall.com/lists/oss-security/2018/09/25/4http://www.openwall.com/lists/oss-security/2021/07/20/2http://www.securityfocus.com/bid/105407https://access.redhat.com/errata/RHSA-2018:2748https://access.redhat.com/errata/RHSA-2018:2763https://access.redhat.com/errata/RHSA-2018:2846https://access.redhat.com/errata/RHSA-2018:2924https://access.redhat.com/errata/RHSA-2018:2925https://access.redhat.com/errata/RHSA-2018:2933https://access.redhat.com/errata/RHSA-2018:3540https://access.redhat.com/errata/RHSA-2018:3586https://access.redhat.com/errata/RHSA-2018:3590https://access.redhat.com/errata/RHSA-2018:3591https://access.redhat.com/errata/RHSA-2018:3643https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14634https://security.netapp.com/advisory/ntap-20190204-0002/https://security.paloaltonetworks.com/CVE-2018-14634https://support.f5.com/csp/article/K20934447?utm_source=f5support&%3Butm_medium=RSShttps://usn.ubuntu.com/3775-1/https://usn.ubuntu.com/3775-2/https://usn.ubuntu.com/3779-1/https://www.exploit-db.com/exploits/45516/https://www.openwall.com/lists/oss-security/2018/09/25/4https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2018-14634
2018-09-25
Published
2026-01-26
Added to CISA KEV
Exploited in the wild