CVE-2014-0038: Linux Kernel
Medium severity, CVSS 6.9. EPSS: 35.5% chance of exploitation in the next 30 days.
The compat_sys_recvmmsg function in net/compat.c in the Linux kernel before 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to gain privileges via a recvmmsg system call with a crafted timeout pointer parameter.
Affected products
- Linux Linux Kernel: from 3.4, before 3.4.79 (fixed in 3.4.79); from 3.5, before 3.10.29 (fixed in 3.10.29); from 3.11, before 3.12.10 (fixed in 3.12.10); from 3.13, before 3.13.2 (fixed in 3.13.2)
- Opensuse Opensuse: version 12.3 only
Published 2014-02-06. Last modified 2026-06-17.