CVE-2014-2038: Canonical Ubuntu Linux

Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.

The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memory in opportunistic circumstances by writing to a file in an NFS filesystem and then reading the same file.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 13.10 only
  • Linux Linux Kernel: before 3.13.3 (fixed in 3.13.3)

Published 2014-02-28. Last modified 2026-06-17.