peter bassill · operator
$ cve CVE-2018-14634 JSON

CVE-2018-14634 KEV EXPLOIT

7.8
HIGH · CVSS 3.0 · EPSS 14.7% (pctl 97)

Patch first

On CISA KEV — known exploited in the wild, due 2026-02-16.

Description

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.

Scoring

CVSS7.8 (HIGH, v3.0)
VectorCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS14.69% — more likely to be exploited than 97% of all CVEs
WeaknessCWE-190
On CISA KEVyes — remediate by 2026-02-16
Public exploityes
Published2018-09-25
Last modified2026-06-17

CISA KEV

NameLinux Kernel Integer Overflow Vulnerability
Added2026-01-26
Due2026-02-16
Vendor / productLinux / Kernel
Ransomware usenone reported

Affected (28)

VendorProduct
canonicalubuntu linux
f5big-ip access policy manager
f5big-ip advanced firewall manager
f5big-ip analytics
f5big-ip application acceleration manager
f5big-ip application security manager
f5big-ip domain name system
f5big-ip edge gateway
f5big-ip fraud protection service
f5big-ip global traffic manager
f5big-ip link controller
f5big-ip local traffic manager
f5big-ip policy enforcement manager
f5big-ip webaccelerator
f5big-iq centralized management
f5big-iq cloud and orchestration
f5enterprise manager
f5iworkflow
f5traffix signaling delivery controller
linuxlinux kernel
netappsnapprotect
paloaltonetworkspan-os
redhatenterprise linux desktop
redhatenterprise linux server
redhatenterprise linux server aus
redhatenterprise linux server eus
redhatenterprise linux server tus
redhatenterprise linux workstation

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD