CVE-2014-2568: Canonical Ubuntu Linux

Low severity, CVSS 2.9. EPSS: 1% chance of exploitation in the next 30 days.

Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. NOTE: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vulnerability was announced.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only
  • Linux Linux Kernel: from 3.0, up to and including 3.13.6

Published 2014-03-24. Last modified 2026-06-17.