peter bassill · operator
$ cve CVE-2014-0196 JSON

CVE-2014-0196 KEV EXPLOIT

5.5
MEDIUM · CVSS 3.1 · EPSS 22.5% (pctl 98)

Patch first

On CISA KEV — known exploited in the wild, due 2023-06-02.

Description

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

Scoring

CVSS5.5 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS22.48% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-362
On CISA KEVyes — remediate by 2023-06-02
Public exploityes
Published2014-05-07
Last modified2026-06-17

CISA KEV

NameLinux Kernel Race Condition Vulnerability
Added2023-05-12
Due2023-06-02
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (30)

VendorProduct
canonicalubuntu linux
debiandebian linux
f5big-ip access policy manager
f5big-ip advanced firewall manager
f5big-ip analytics
f5big-ip application acceleration manager
f5big-ip application security manager
f5big-ip edge gateway
f5big-ip global traffic manager
f5big-ip link controller
f5big-ip local traffic manager
f5big-ip policy enforcement manager
f5big-ip protocol security module
f5big-ip wan optimization manager
f5big-ip webaccelerator
f5big-iq application delivery controller
f5big-iq centralized management
f5big-iq cloud
f5big-iq cloud and orchestration
f5big-iq device
f5big-iq security
f5enterprise manager
linuxlinux kernel
oraclelinux
redhatenterprise linux
redhatenterprise linux eus
redhatenterprise linux server eus
susesuse linux enterprise desktop
susesuse linux enterprise high availability extension
susesuse linux enterprise server

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD