← All CVEs

CVE-2018-14634

high · 7.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Added 2026-01-26Remediation due 2026-02-16

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.

7.8
CVSS
14.7%
EPSS (exploit prob.)
97th
EPSS percentile
2018-09-25
Published

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-190

Affected products

VendorProductAffected versions
paloaltonetworkspan-os>= 7.1.0, < 7.1.23
paloaltonetworkspan-os>= 8.0.0, < 8.0.16
paloaltonetworkspan-os>= 8.1.0, < 8.1.7
f5big-ip_access_policy_manager>= 11.2.1, < 11.6.4
f5big-ip_access_policy_manager>= 12.1.0, < 12.1.5
f5big-ip_access_policy_manager>= 13.0.0, < 13.1.1.5
f5big-ip_access_policy_manager>= 14.0.0, < 14.0.1.1
f5big-ip_access_policy_manager>= 14.1.0, < 14.1.0.6
f5big-ip_advanced_firewall_manager>= 11.2.1, < 11.6.4
f5big-ip_advanced_firewall_manager>= 12.1.0, < 12.1.5
f5big-ip_advanced_firewall_manager>= 13.0.0, < 13.1.1.5
f5big-ip_advanced_firewall_manager>= 14.0.0, < 14.0.1.1
f5big-ip_advanced_firewall_manager>= 14.1.0, < 14.1.0.6
f5big-ip_analytics>= 11.2.1, < 11.6.4
f5big-ip_analytics>= 12.1.0, < 12.1.5
f5big-ip_analytics>= 13.0.0, < 13.1.1.5
f5big-ip_analytics>= 14.0.0, < 14.0.1.1
f5big-ip_analytics>= 14.1.0, < 14.1.0.6
f5big-ip_application_acceleration_manager>= 11.2.1, < 11.6.4
f5big-ip_application_acceleration_manager>= 12.1.0, < 12.1.5
f5big-ip_application_acceleration_manager>= 13.0.0, < 13.1.1.5
f5big-ip_application_acceleration_manager>= 14.0.0, < 14.0.1.1
f5big-ip_application_acceleration_manager>= 14.1.0, < 14.1.0.6
f5big-ip_application_security_manager>= 11.2.1, < 11.6.4
f5big-ip_application_security_manager>= 12.1.0, < 12.1.5
f5big-ip_application_security_manager>= 13.0.0, < 13.1.1.5
f5big-ip_application_security_manager>= 14.0.0, < 14.0.1.1
f5big-ip_application_security_manager>= 14.1.0, < 14.1.0.6
f5big-ip_domain_name_system>= 11.2.1, < 11.6.4
f5big-ip_domain_name_system>= 12.1.0, < 12.1.5
f5big-ip_domain_name_system>= 13.0.0, < 13.1.1.5
f5big-ip_domain_name_system>= 14.0.0, < 14.0.1.1
f5big-ip_domain_name_system>= 14.1.0, < 14.1.0.6
f5big-ip_edge_gateway>= 11.2.1, < 11.6.4
f5big-ip_edge_gateway>= 12.1.0, < 12.1.5
f5big-ip_edge_gateway>= 13.0.0, < 13.1.1.5
f5big-ip_edge_gateway>= 14.0.0, < 14.0.1.1
f5big-ip_edge_gateway>= 14.1.0, < 14.1.0.6
f5big-ip_fraud_protection_service>= 11.2.1, < 11.6.4
f5big-ip_fraud_protection_service>= 12.1.0, < 12.1.5

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2018-14634