CVE-2014-2851: Debian Linux
Medium severity, CVSS 6.9. EPSS: 1% chance of exploitation in the next 30 days.
Integer overflow in the ping_init_sock function in net/ipv4/ping.c in the Linux kernel through 3.14.1 allows local users to cause a denial of service (use-after-free and system crash) or possibly gain privileges via a crafted application that leverages an improperly managed reference counter.
Affected products
- Debian Debian Linux: version 7.0 only
- Linux Linux Kernel: from 3.0, before 3.2.60 (fixed in 3.2.60); from 3.3, before 3.4.92 (fixed in 3.4.92); from 3.5, before 3.10.41 (fixed in 3.10.41); from 3.11, before 3.12.19 (fixed in 3.12.19); from 3.13, before 3.14.5 (fixed in 3.14.5); version 3.0 only
Published 2014-04-14. Last modified 2026-06-17.