CVE-2014-5220: Mdadm Project Mdadm
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
The mdcheck script of the mdadm package for openSUSE 13.2 prior to version 3.3.1-5.14.1 does not properly sanitize device names, which allows local attackers to execute arbitrary commands as root.
Affected products
- Mdadm Project Mdadm: before 3.3.3 (fixed in 3.3.3)
- Opensuse Opensuse: version 13.2 only
Published 2018-06-08. Last modified 2026-06-17.