CVE-2014-4027: Canonical Ubuntu Linux

Low severity, CVSS 2.3. EPSS: 0.7% chance of exploitation in the next 30 days.

The rd_build_device_space function in drivers/target/target_core_rd.c in the Linux kernel before 3.14 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from ramdisk_mcp memory by leveraging access to a SCSI initiator.

Affected products

  • Canonical Ubuntu Linux: version 12.04 only
  • F5 BIG-IP Access Policy Manager: from 11.1.0, up to and including 11.6.0; version 12.0.0 only
  • F5 BIG-IP Advanced Firewall Manager: from 11.3.0, up to and including 11.6.0; version 12.0.0 only
  • F5 BIG-IP Analytics: from 11.1.0, up to and including 11.6.0; version 12.0.0 only
  • F5 BIG-IP Application Acceleration Manager: from 11.4.0, up to and including 11.6.0; version 12.0.0 only
  • F5 BIG-IP Application Security Manager: from 11.1.0, up to and including 11.6.0; version 12.0.0 only
  • F5 BIG-IP Domain Name System: version 12.0.0 only
  • F5 BIG-IP Edge Gateway: from 11.1.0, up to and including 11.3.0
  • F5 BIG-IP Global Traffic Manager: from 11.1.0, up to and including 11.6.0
  • F5 BIG-IP Link Controller: from 11.1.0, up to and including 11.6.0; version 12.0.0 only
  • F5 BIG-IP Local Traffic Manager: from 11.1.0, up to and including 11.6.0; version 12.0.0 only
  • F5 BIG-IP Policy Enforcement Manager: from 11.3.0, up to and including 11.6.0; version 12.0.0 only
  • F5 BIG-IP Protocol Security Module: from 11.1.0, up to and including 11.4.1
  • F5 BIG-IP WAN Optimization Manager: from 11.1.0, up to and including 11.3.0
  • F5 BIG-IP Webaccelerator: from 11.1.0, up to and including 11.3.0
  • F5 BIG-IQ Application Delivery Controller: version 4.5.0 only
  • F5 BIG-IQ Cloud: from 4.0.0, up to and including 4.5.0
  • F5 BIG-IQ Device: from 4.2.0, up to and including 4.5.0
  • F5 BIG-IQ Security: from 4.0.0, up to and including 4.5.0
  • F5 Enterprise Manager: from 3.0.0, up to and including 3.1.1
  • Linux Linux Kernel: before 3.14 (fixed in 3.14)
  • Red Hat Enterprise Linux: version 6.0 only
  • Suse Linux Enterprise Desktop: version 11 only
  • Suse Linux Enterprise High Availability Extension: version 11 only
  • Suse Linux Enterprise Real Time Extension: version 11 only
  • and 1 more

Published 2014-06-23. Last modified 2026-06-17.