CVE-2014-0038
EPSS 34.6%
Description
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.
How to fix CVE-2014-0038
To remediate CVE-2014-0038, upgrade the affected package to a fixed version below.
- Debian/linux—upgrade to 3.13.4-1 or later
Is CVE-2014-0038 being exploited?
Moderate — EPSS is 34.6%. Track this CVE but it's not at the top of the prioritisation list.
Affected packages (1)
- from 0, < 3.13.4-1