CVE-2014-3917

low
Published 2014-06-05 · Modified 2026-05-06
CVSS v3
CVSS v2
3.3
VIR risk
3.3

Description

kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-3917

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.14.7-1
debian debianbullseyefixed3.14.7-1
debian debianforkyfixed3.14.7-1
debian debiansidfixed3.14.7-1
debian debiantrixiefixed3.14.7-1
suse suse10.0affected
linux linux-kernelaffected
linux linux-kernel3.14affected
linux linux-kernel3.14.1affected
linux linux-kernel3.14.2affected
linux linux-kernel3.14.3affected
linux linux-kernel3.14.4affected
redhat rhel5affected
redhat rhel6.0affected

References

CWEs

CWE-200

Verify integrity in audit chain (admin only). AS-IS.