CVE-2014-3917 PUBLISHED

kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number.

EPSS 0.09% · 25.3th percentile

Risk Scores

EPSS Score
0.09%
25.3th percentile

Affected Products

VendorProductVersions
Ubuntu:14.04:LTSlinux3.13.0-27.50, 3.11.0-12.19, 0

Timeline

References

Open in Interactive Console →