CVE-2014-9903 is a Linux kernel vulnerability affecting versions 3.14-rc before 3.14-rc4, where an incorrect size calculation in the sched_read_attr function allows local users to extract sensitive information from kernel stack memory. Rated Medium (CVSS 5.5), this low-complexity vulnerability requires local access and can lead to high confidentiality impact. There is no evidence of active exploitation, public exploit code, or significant community discussion, indicating a low current threat level.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.14:rc1:*:*:*:*:*:* | ||
3.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.14:rc2:*:*:*:*:*:* | ||
3.14CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.14:rc3:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.