CVE-2014-3182: Linux Kernel
Medium severity, CVSS 6.9. EPSS: 0.4% chance of exploitation in the next 30 days.
Array index error in the logi_dj_raw_event function in drivers/hid/hid-logitech-dj.c in the Linux kernel before 3.16.2 allows physically proximate attackers to execute arbitrary code or cause a denial of service (invalid kfree) via a crafted device that provides a malformed REPORT_TYPE_NOTIF_DEVICE_UNPAIRED value.
Affected products
- Linux Linux Kernel: before 3.2.63 (fixed in 3.2.63); from 3.3, before 3.4.104 (fixed in 3.4.104); from 3.5, before 3.10.54 (fixed in 3.10.54); from 3.11, before 3.12.28 (fixed in 3.12.28); from 3.13, before 3.14.18 (fixed in 3.14.18); from 3.15, before 3.16.2 (fixed in 3.16.2)
Published 2014-09-28. Last modified 2026-06-17.