Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-3534

20
FAUCET Score

CVE-2014-3534 is a local privilege escalation vulnerability affecting the Linux kernel before version 3.15.8 on the s390 platform. It arises from improper restrictions in address-space control operations during PTRACE_POKEUSR_AREA requests, allowing local users to gain read and write access to kernel memory. This vulnerability carries a CVSS score of 7.2, indicating high severity with local access, low complexity, and complete confidentiality, integrity, and availability impacts. There is no known active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.2.62CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.3, < 3.4.101CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.5, < 3.10.51CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.11, < 3.12.27CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.13, < 3.14.15CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

7.2HIGH

AV:L/AC:L/Au:N/C:C/I:C/A:C

Confidentiality Impact
COMPLETE
Integrity Impact
COMPLETE
Availability Impact
COMPLETE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
10.0
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.47%
Probability of exploitation in next 30 days
EPSS Percentile
38.0%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0047 is in the 57th percentile among its peer group of 3,241 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.5 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-123.6.3.el7
View patch

Vendor Advisories (1)

redhatCVE-2014-3534Important

kernel: s390: ptrace: insufficient sanitization when setting psw mask

Jul 21, 2014

References

git.kernel.org
Broken Link
bugzilla.redhat.com / show_bug.cgi
Issue TrackingThird Party Advisory
secunia.com / advisories/59790
Third Party Advisory
secunia.com / advisories/60351
Third Party Advisory
exchange.xforce.ibmcloud.com / vulnerabilities/95069
Third Party AdvisoryVDB Entry
github.com / torvalds/linux/commit/dab6cf55f81a6e16b8147aed9a843e1691dcd318
PatchThird Party Advisory
debian.org / security/2014/dsa-2992
Third Party Advisory
kernel.org / pub/linux/kernel/v3.x/ChangeLog-3.15.8
Release NotesVendor Advisory
osvdb.org / 109546
Broken Link
securityfocus.com / bid/68940
Third Party AdvisoryVDB Entry
securitytracker.com / id/1030683
Third Party AdvisoryVDB Entry