CVE-2014-3180 describes a critical out-of-bounds read vulnerability in the Linux kernel, specifically in kernel/compat.c, affecting versions prior to 3.17, including Google Chrome OS. The flaw, rated 9.1 Critical, could allow an unauthenticated attacker to cause a denial of service or potentially disclose sensitive information due to uninitialized data being used during compat_sys_nanosleep restarts. Despite its high severity, the exploitability of this vulnerability is disputed due to an unreachable code path, and there is no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.17CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:google:chrome_os:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.