CVE-2014-3917

Severity CVSS v4.0:
Pending analysis
Type:
CWE-200 Information Leak / Disclosure
Publication date:
05/06/2014
Last modified:
12/04/2025

Description

kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:suse:linux_enterprise_desktop:10.0:sp4:*:*:lts:*:*:*
cpe:2.3:o:redhat:enterprise_linux:5:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_linux:6.0:*:*:*:*:*:*:*
cpe:2.3:o:redhat:enterprise_mrg:2.0:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* 3.14.5 (including)
cpe:2.3:o:linux:linux_kernel:3.14:-:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.14:rc1:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.14:rc2:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.14:rc3:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.14:rc4:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.14:rc5:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.14:rc6:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.14:rc7:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.14:rc8:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:3.14.1:*:*:*:*:*:*:*