PT-2014-1014 · Linux+2 · Linux Kernel+2

Rebel

·

Published

2014-01-15

·

Updated

2025-09-29

·

CVE-2014-0038

CVSS v2.0

6.9

Medium

VectorAV:L/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.13.2
Description The issue allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter. This is related to the compat sys recvmmsg function in net/compat.c when CONFIG X86 X32 is enabled.
Recommendations For Linux kernel versions prior to 3.13.2, update to version 3.13.2 or later to resolve the issue. As a temporary workaround, consider restricting access to the recvmmsg system call to minimize the risk of exploitation.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2025_16880
ALT-PU-2014-1124
ALT-PU-2014-1125
ALT-PU-2014-1174
ALT-PU-2014-2064
BDU:2014-00065
CVE-2014-0038
ELSA-2014-3034
MGASA-2014-0038
MGASA-2014-0039
MGASA-2014-0043
MGASA-2014-0044
MGASA-2014-0045
MGASA-2014-0046
MGASA-2014-0055
MGASA-2014-0061
MGASA-2014-0063
MGASA-2014-0064
OPENSUSE-SU-2014_0204-1
OPENSUSE-SU-2014_0205-1
OPENSUSE-SU-2024:10128-1
SUSE-SU-2017:3210-1
SUSE-SU-2017:3249-1
SUSE-SU-2017_3210-1
SUSE-SU-2017_3249-1

Affected Products

Alt Linux
Linux Kernel
Suse