CVE-2014-3917: Linux Kernel

Low severity, CVSS 3.3. EPSS: 0.4% chance of exploitation in the next 30 days.

kernel/auditsc.c in the Linux kernel through 3.14.5, when CONFIG_AUDITSYSCALL is enabled with certain syscall rules, allows local users to obtain potentially sensitive single-bit values from kernel memory or cause a denial of service (OOPS) via a large value of a syscall number.

Affected products

  • Linux Linux Kernel: up to and including 3.14.5; version 3.14 only; version 3.14.1 only; version 3.14.2 only; version 3.14.3 only; version 3.14.4 only
  • Red Hat Enterprise Linux: version 5 only; version 6.0 only
  • Red Hat Enterprise Mrg: version 2.0 only
  • Suse Linux Enterprise Desktop: version 10.0 only

Published 2014-06-05. Last modified 2026-06-17.