CVE-2014-3940: Linux Kernel

Medium severity, CVSS 4.0. EPSS: 0.3% chance of exploitation in the next 30 days.

The Linux kernel through 3.14.5 does not properly consider the presence of hugetlb entries, which allows local users to cause a denial of service (memory corruption or system crash) by accessing certain memory locations, as demonstrated by triggering a race condition via numa_maps read operations during hugepage migration, related to fs/proc/task_mmu.c and mm/mempolicy.c.

Affected products

  • Linux Linux Kernel: up to and including 3.14.5; version 3.14 only; version 3.14.1 only; version 3.14.2 only; version 3.14.3 only; version 3.14.4 only
  • Red Hat Enterprise Linux: version 6.0 only
  • Red Hat Enterprise Mrg: version 2.0 only

Published 2014-06-05. Last modified 2026-06-17.