CVE-2014-1874: Canonical Ubuntu Linux
Medium severity, CVSS 4.9. EPSS: 0.6% chance of exploitation in the next 30 days.
The security_context_to_sid_core function in security/selinux/ss/services.c in the Linux kernel before 3.13.4 allows local users to cause a denial of service (system crash) by leveraging the CAP_MAC_ADMIN capability to set a zero-length security context.
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 12.10 only; version 13.10 only
- Linux Linux Kernel: before 3.13.4 (fixed in 3.13.4)
- Suse Linux Enterprise Server: version 10 only
Published 2014-02-28. Last modified 2026-06-17.