CVE-2014-2851 is an integer overflow vulnerability in the Linux kernel's ping_init_sock function, affecting Debian and other Linux distributions. This flaw allows a local attacker to trigger a use-after-free condition, leading to a denial of service or potential privilege escalation. With a CVSS score of 6.9, it has a medium attack complexity but high impact on confidentiality, integrity, and availability. While not actively exploited in the wild (KEV), an ExploitDB entry exists (EDB-32926), and there has been some community discussion regarding its exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 3.0, < 3.2.60CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.3, < 3.4.92CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.5, < 3.10.41CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.11, < 3.12.19CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
>= 3.13, < 3.14.5CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.