Skip to content

CVE-2014-0181

The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.

View on NVD

Severity

N/A

EPSS

Probability of exploitation (next 30 days): 0.0003 (0.0%)
Percentile: 7.0%
EPSS: 2026-05-06

Affects

linux:linux_kernelopensuse:evergreenredhat:enterprise_linux_desktopredhat:enterprise_linux_serversuse:linux_enterprise_real_time_extensionsuse:linux_enterprise_serversuse:suse_linux_enterprise_server

Technical description

The Netlink implementation in the Linux kernel through 3.14.1 does not provide a mechanism for authorizing socket operations based on the opener of a socket, which allows local users to bypass intended access restrictions and modify network configurations by using a Netlink socket for the (1) stdout or (2) stderr of a setuid program.

Published: 4/27/2014, 12:55:05 AM
Last modified: 5/6/2026, 10:30:45 PM

References

HomeEventsBlogResourcesTeam