CVE-2014-2038: Canonical Ubuntu Linux
Low severity, CVSS 2.1. EPSS: 0.4% chance of exploitation in the next 30 days.
The nfs_can_extend_write function in fs/nfs/write.c in the Linux kernel before 3.13.3 relies on a write delegation to extend a write operation without a certain up-to-date verification, which allows local users to obtain sensitive information from kernel memory in opportunistic circumstances by writing to a file in an NFS filesystem and then reading the same file.
Affected products
- Canonical Ubuntu Linux: version 12.04 only; version 13.10 only
- Linux Linux Kernel: before 3.13.3 (fixed in 3.13.3)
Published 2014-02-28. Last modified 2026-06-17.