CVE-2014-4014 is a local privilege escalation vulnerability affecting the Linux kernel prior to version 3.14.8. It allows a local user to bypass chmod restrictions by creating a user namespace, enabling them to set the setgid bit on a file owned by root. With a CVSS score of 6.2, this vulnerability has a local attack vector and high attack complexity, but can lead to complete compromise of confidentiality, integrity, and availability. While not listed on the KEV catalog or Hot List, one public exploit (EDB-33824) exists, and there has been minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 3.14.8CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:H/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.