CVE-2014-0181

low
Published 2014-04-27 · Modified 2026-05-06
CVSS v3
CVSS v2
2.1
VIR risk
2.1

Description

The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-0181

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.9

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.10.45

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://git.kernel.org/cgit/linux/kernel/git/davem/net.git/commit/?id=90f62cf30a78721641e08737bda787552428061e

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.14.9-1
debian debianbullseyefixed3.14.9-1
debian debianforkyfixed3.14.9-1
debian debiansidfixed3.14.9-1
debian debiantrixiefixed3.14.9-1
redhat rhel5affected
redhat rhel5.0affected
suse suse10affected
suse suse11affected
linux linux-kernelaffected

References

CWEs

CWE-264

Verify integrity in audit chain (admin only). AS-IS.