CVE-2014-1739: Canonical Ubuntu Linux

Low severity, CVSS 2.1. EPSS: 1.1% chance of exploitation in the next 30 days.

The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0 read access for a MEDIA_IOC_ENUM_ENTITIES ioctl call.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 13.10 only
  • Linux Linux Kernel: before 3.14.6 (fixed in 3.14.6)
  • Suse Linux Enterprise High Availability Extension: version 11 only
  • Suse Suse Linux Enterprise Desktop: version 11 only
  • Suse Suse Linux Enterprise Server: version 11 only

Published 2014-06-23. Last modified 2026-06-17.