Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-0038

63
FAUCET Score

CVE-2014-0038 is a local privilege escalation vulnerability in the Linux kernel versions before 3.13.2, specifically affecting systems with CONFIG_X86_X32 enabled. It allows local users to gain elevated privileges by crafting a recvmmsg system call with a malicious timeout pointer. This vulnerability has a CVSS score of 6.9, indicating high severity with local access and medium attack complexity, leading to complete compromise of confidentiality, integrity, and availability. Exploit intelligence shows multiple public exploits, including Metasploit modules and ExploitDB entries, confirming its exploitability. The vulnerability has garnered significant community discussion and media coverage, highlighting its potential impact.

Impacted Technologies

VendorProductVersion(s)CPE
>= 3.4, < 3.4.79CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.5, < 3.10.29CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.11, < 3.12.10CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.13, < 3.13.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
12.3CPE matchmatch criteria
cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

6.9MEDIUM

AV:L/AC:M/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
MEDIUM
Authentication
NONE
Exploitability Score
3.4
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
35.45%
Probability of exploitation in next 30 days
EPSS Percentile
98.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-28
Model: v2026.06.15
Metasploit: Linux Kernel recvmmsg Privilege Escalation · Feb 2, 2014
ExploitDB: EDB-40503 · Oct 11, 2016
This CVE's current EPSS score of 0.3545 is in the 100th percentile among its peer group of 1,595 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (1)

github_advisorypatch availablevia nvd_reference
View patch

Vendor Advisories (1)

redhatCVE-2014-0038Important

Kernel: 3.4+ arbitrary write with CONFIG_X86_X32

Jan 31, 2014

References

git.kernel.org
Third Party AdvisoryVDB Entry
lists.opensuse.org / opensuse-security-announce/2014-02/msg00002.html
Third Party AdvisoryVDB Entry
lists.opensuse.org / opensuse-security-announce/2014-02/msg00003.html
Third Party AdvisoryVDB Entry
pastebin.com / raw.php
Exploit
bugzilla.redhat.com / show_bug.cgi
Issue Tracking
code.google.com / p/chromium/issues/detail
Third Party Advisory
secunia.com / advisories/56669
Not Applicable
github.com / saelo/cve-2014-0038
Third Party Advisory
github.com / torvalds/linux/commit/2def2ef2ae5f3990aabdbe8a755911902707d268
ExploitPatch
exploit-db.com / exploits/40503
Third Party AdvisoryVDB Entry
exploit-db.com / exploits/31346
Third Party AdvisoryVDB Entry
exploit-db.com / exploits/31347
Third Party AdvisoryVDB Entry
kernel.org / pub/linux/kernel/v3.x/ChangeLog-3.13.2
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
openwall.com / lists/oss-security/2014/01/31/2
Mailing List
securityfocus.com / bid/65255
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2094-1
Third Party Advisory
ubuntu.com / usn/USN-2095-1
Third Party Advisory
ubuntu.com / usn/USN-2096-1
Third Party Advisory