CVE-2018-14634
high · 7.8Actively exploitedOn the CISA Known Exploited Vulnerabilities catalog
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Added 2026-01-26Remediation due 2026-02-16
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
7.8
CVSS
14.7%
EPSS (exploit prob.)
97th
EPSS percentile
2018-09-25
Published
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-190
Affected products
| Vendor | Product | Affected versions |
|---|---|---|
| paloaltonetworks | pan-os | >= 7.1.0, < 7.1.23 |
| paloaltonetworks | pan-os | >= 8.0.0, < 8.0.16 |
| paloaltonetworks | pan-os | >= 8.1.0, < 8.1.7 |
| f5 | big-ip_access_policy_manager | >= 11.2.1, < 11.6.4 |
| f5 | big-ip_access_policy_manager | >= 12.1.0, < 12.1.5 |
| f5 | big-ip_access_policy_manager | >= 13.0.0, < 13.1.1.5 |
| f5 | big-ip_access_policy_manager | >= 14.0.0, < 14.0.1.1 |
| f5 | big-ip_access_policy_manager | >= 14.1.0, < 14.1.0.6 |
| f5 | big-ip_advanced_firewall_manager | >= 11.2.1, < 11.6.4 |
| f5 | big-ip_advanced_firewall_manager | >= 12.1.0, < 12.1.5 |
| f5 | big-ip_advanced_firewall_manager | >= 13.0.0, < 13.1.1.5 |
| f5 | big-ip_advanced_firewall_manager | >= 14.0.0, < 14.0.1.1 |
| f5 | big-ip_advanced_firewall_manager | >= 14.1.0, < 14.1.0.6 |
| f5 | big-ip_analytics | >= 11.2.1, < 11.6.4 |
| f5 | big-ip_analytics | >= 12.1.0, < 12.1.5 |
| f5 | big-ip_analytics | >= 13.0.0, < 13.1.1.5 |
| f5 | big-ip_analytics | >= 14.0.0, < 14.0.1.1 |
| f5 | big-ip_analytics | >= 14.1.0, < 14.1.0.6 |
| f5 | big-ip_application_acceleration_manager | >= 11.2.1, < 11.6.4 |
| f5 | big-ip_application_acceleration_manager | >= 12.1.0, < 12.1.5 |
| f5 | big-ip_application_acceleration_manager | >= 13.0.0, < 13.1.1.5 |
| f5 | big-ip_application_acceleration_manager | >= 14.0.0, < 14.0.1.1 |
| f5 | big-ip_application_acceleration_manager | >= 14.1.0, < 14.1.0.6 |
| f5 | big-ip_application_security_manager | >= 11.2.1, < 11.6.4 |
| f5 | big-ip_application_security_manager | >= 12.1.0, < 12.1.5 |
| f5 | big-ip_application_security_manager | >= 13.0.0, < 13.1.1.5 |
| f5 | big-ip_application_security_manager | >= 14.0.0, < 14.0.1.1 |
| f5 | big-ip_application_security_manager | >= 14.1.0, < 14.1.0.6 |
| f5 | big-ip_domain_name_system | >= 11.2.1, < 11.6.4 |
| f5 | big-ip_domain_name_system | >= 12.1.0, < 12.1.5 |
| f5 | big-ip_domain_name_system | >= 13.0.0, < 13.1.1.5 |
| f5 | big-ip_domain_name_system | >= 14.0.0, < 14.0.1.1 |
| f5 | big-ip_domain_name_system | >= 14.1.0, < 14.1.0.6 |
| f5 | big-ip_edge_gateway | >= 11.2.1, < 11.6.4 |
| f5 | big-ip_edge_gateway | >= 12.1.0, < 12.1.5 |
| f5 | big-ip_edge_gateway | >= 13.0.0, < 13.1.1.5 |
| f5 | big-ip_edge_gateway | >= 14.0.0, < 14.0.1.1 |
| f5 | big-ip_edge_gateway | >= 14.1.0, < 14.1.0.6 |
| f5 | big-ip_fraud_protection_service | >= 11.2.1, < 11.6.4 |
| f5 | big-ip_fraud_protection_service | >= 12.1.0, < 12.1.5 |
Check a specific version with /api/v1/cve/match.
References
- http://www.openwall.com/lists/oss-security/2021/07/20/2
- http://www.securityfocus.com/bid/105407
- https://access.redhat.com/errata/RHSA-2018:2748
- https://access.redhat.com/errata/RHSA-2018:2763
- https://access.redhat.com/errata/RHSA-2018:2846
- https://access.redhat.com/errata/RHSA-2018:2924
- https://access.redhat.com/errata/RHSA-2018:2925
- https://access.redhat.com/errata/RHSA-2018:2933
- https://access.redhat.com/errata/RHSA-2018:3540
- https://access.redhat.com/errata/RHSA-2018:3586
- https://access.redhat.com/errata/RHSA-2018:3590
- https://access.redhat.com/errata/RHSA-2018:3591
- https://access.redhat.com/errata/RHSA-2018:3643
- https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14634
- https://security.netapp.com/advisory/ntap-20190204-0002/
- https://security.paloaltonetworks.com/CVE-2018-14634
- https://support.f5.com/csp/article/K20934447?utm_source=f5support&%3Butm_medium=RSS
- https://usn.ubuntu.com/3775-1/
- https://usn.ubuntu.com/3775-2/
- https://usn.ubuntu.com/3779-1/
- https://www.exploit-db.com/exploits/45516/
- https://www.openwall.com/lists/oss-security/2018/09/25/4
- http://www.openwall.com/lists/oss-security/2021/07/20/2
- http://www.securityfocus.com/bid/105407
- https://access.redhat.com/errata/RHSA-2018:2748
Query this programmatically:
curl https://evil-db.io/api/v1/cve/CVE-2018-14634