CVE-2014-1690

low
Published 2014-02-28 · Modified 2026-04-29
CVSS v3
CVSS v2
2.6
VIR risk
2.6

Description

The help function in net/netfilter/nf_nat_irc.c in the Linux kernel before 3.12.8 allows remote attackers to obtain sensitive information from kernel memory by establishing an IRC DCC session in which incorrect packet data is transmitted during use of the NAT mangle feature.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-1690

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/torvalds/linux/commit/2690d97ade05c5325cbf7c72b94b90d265659886

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://bugzilla.redhat.com/show_bug.cgi?id=1058748

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.openwall.com/lists/oss-security/2014/01/28/3

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.12.8

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.12.8-1
debian debianbullseyefixed3.12.8-1
debian debianforkyfixed3.12.8-1
debian debiansidfixed3.12.8-1
debian debiantrixiefixed3.12.8-1
ubuntu ubuntu12.04affected
ubuntu ubuntu13.10affected
linux linux-kernelaffected3.12.8

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.