CVE-2014-0077 describes a memory corruption vulnerability in the Linux kernel's vhost network driver (drivers/vhost/net.c) affecting versions prior to 3.13.10. This flaw allows a malicious guest OS user to trigger a denial of service (host OS crash) or potentially gain privileges on the host by sending crafted packets when mergeable buffers are disabled. The vulnerability has a CVSS score of 5.5, indicating a medium severity with an adjacent attack vector and high attack complexity. There is no public exploit intelligence, Metasploit modules, or Nuclei templates available, and it has not been added to CISA's KEV catalog. Community discussion and media coverage for this CVE are minimal.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.13.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:A/AC:H/Au:S/C:P/I:P/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.