CVE-2014-1874: Canonical Ubuntu Linux

Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.

The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_ADMIN capability to set a zero-length security context.

Affected products

  • Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.10 only
  • Linux Linux Kernel: before 3.13.4 (fixed in 3.13.4)
  • Suse Linux Enterprise Server: version 10 only

Published 2014-02-28. Last modified 2026-06-17.