CVE-2014-3181: Linux Kernel

Medium severity, CVSS 6.9. EPSS: 0.8% chance of exploitation in the next 30 days.

Multiple stack-based buffer overflows in the magicmouse_raw_event function in drivers/hid/hid-magicmouse.c in the Magic Mouse HID driver in the Linux kernel through 3.16.3 allow physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that provides a large amount of (1) EHCI or (2) XHCI data associated with an event.

Affected products

  • Linux Linux Kernel: from 2.6.37, before 3.2.63 (fixed in 3.2.63); from 3.3, before 3.4.104 (fixed in 3.4.104); from 3.5, before 3.10.56 (fixed in 3.10.56); from 3.11, before 3.12.31 (fixed in 3.12.31); from 3.13, before 3.14.20 (fixed in 3.14.20); from 3.15, before 3.16.4 (fixed in 3.16.4)

Published 2014-09-28. Last modified 2026-06-17.