CVE-2014-1739: Canonical Ubuntu Linux
Low severity, CVSS 2.1. EPSS: 1.1% chance of exploitation in the next 30 days.
The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0 read access for a MEDIA_IOC_ENUM_ENTITIES ioctl call.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 13.10 only
- Linux Linux Kernel: before 3.14.6 (fixed in 3.14.6)
- Suse Linux Enterprise High Availability Extension: version 11 only
- Suse Suse Linux Enterprise Desktop: version 11 only
- Suse Suse Linux Enterprise Server: version 11 only
Published 2014-06-23. Last modified 2026-06-17.