CVE-2014-3186: Canonical Ubuntu Linux

Medium severity, CVSS 6.9. EPSS: 0.7% chance of exploitation in the next 30 days.

Buffer overflow in the picolcd_raw_event function in devices/hid/hid-picolcd_core.c in the PicoLCD HID device driver in the Linux kernel through 3.16.3, as used in Android on Nexus 7 devices, allows physically proximate attackers to cause a denial of service (system crash) or possibly execute arbitrary code via a crafted device that sends a large report.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only; version 14.04 only
  • Linux Linux Kernel: from 2.6.35, before 3.2.63 (fixed in 3.2.63); from 3.3, before 3.4.104 (fixed in 3.4.104); from 3.5, before 3.10.56 (fixed in 3.10.56); from 3.11, before 3.12.31 (fixed in 3.12.31); from 3.13, before 3.14.20 (fixed in 3.14.20); from 3.15, before 3.16.4 (fixed in 3.16.4)

Published 2014-09-28. Last modified 2026-06-17.