CVE-2014-0038 is a local privilege escalation vulnerability in the Linux kernel versions before 3.13.2, specifically affecting systems with CONFIG_X86_X32 enabled. It allows local users to gain elevated privileges by crafting a recvmmsg system call with a malicious timeout pointer. This vulnerability has a CVSS score of 6.9, indicating high severity with local access and medium attack complexity, leading to complete compromise of confidentiality, integrity, and availability. Exploit intelligence shows multiple public exploits, including Metasploit modules and ExploitDB entries, confirming its exploitability. The vulnerability has garnered significant community discussion and media coverage, highlighting its potential impact.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.4, < 3.4.79CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.5, < 3.10.29CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.11, < 3.12.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.13, < 3.13.2CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
12.3CPE matchmatch criteria | cpe:2.3:o:opensuse:opensuse:12.3:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.