← Back

CVE-2018-14634

nvd nist
Published: Sep 25, 2018Modified: Jan 27, 2026CISA KEV

JSON object

Loading...
7.8
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.

Affected (97)

Show all products
Pan Os
18 products
Big Ip Access Policy Manager
Big Ip Advanced Firewall Manager
Big Ip Analytics
Big Ip Domain Name System
Big Ip Edge Gateway
Big Ip Fraud Protection Service
Big Ip Global Traffic Manager
Big Ip Link Controller
Big Ip Local Traffic Manager
Big Ip Policy Enforcement Manager
Big Ip Webaccelerator
Big Iq Centralized Management
Big Iq Cloud And Orchestration
Enterprise Manager
Iworkflow
1 product
Linux Kernel
6 products
Enterprise Linux Desktop
Enterprise Linux Server
Enterprise Linux Server Aus
Enterprise Linux Server Eus
Enterprise Linux Server Tus
Enterprise Linux Workstation
1 product
Ubuntu Linux
1 product
Snapprotect
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Paloaltonetworks
From 7.1.0 to 7.1.23
From 8.0.0 to 8.0.16
From 8.1.0 to 8.1.7
Configuration B
65 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
F5
From 11.2.1 to 11.6.4
From 12.1.0 to 12.1.5
From 13.0.0 to 13.1.1.5
From 14.0.0 to 14.0.1.1
From 14.1.0 to 14.1.0.6
Configuration C
9 vulnerable
Vulnerable SoftwareAffected Versions
F5
From 5.0.0 to 5.4.0
From 6.0.0 to 6.0.1
From 7.0.0 to 7.1.0
Version 4.6.0
Version 1.0.0
Version 3.1.1
From 2.2.0 to 2.3.0
F5
From 5.0.0 to 5.1.0
Version 4.4.0
Configuration D
3 vulnerable
Vulnerable SoftwareAffected Versions
Linux
From 2.6.0 to 2.6.39.4
From 3.10 to 3.10.102
From 4.14 to 4.14.54
Configuration E
14 vulnerable
Configuration F
2 vulnerable
Vulnerable SoftwareAffected Versions
Canonical
Version 12.04
Version 14.04
Configuration G
1 vulnerable
Vulnerable SoftwareAffected Versions
All versions

References (45)

Source: secalert@redhat.com
Mailing ListThird Party Advisory
Source: secalert@redhat.com
Third Party AdvisoryVDB EntryBroken Link
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Issue TrackingThird Party Advisory
Source: secalert@redhat.com
PatchThird Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
Third Party Advisory
Source: secalert@redhat.com
ExploitThird Party AdvisoryVDB Entry
Source: secalert@redhat.com
ExploitMailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Mailing ListThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB EntryBroken Link
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Issue TrackingThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchThird Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitThird Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
ExploitMailing ListThird Party Advisory
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0
US Government Resource

Timeline

No history available yet.