Synced 30 Sept 2026 20:54 UTC Account
← All products

CVE-2014-2568

LOW severity · CVSS 2.9 · Use-after-free
2.9CVSS LOW

Summary

Use-after-free vulnerability in the nfqnl_zcopy function in net/netfilter/nfnetlink_queue_core.c in the Linux kernel through 3.13.6 allows attackers to obtain sensitive information from kernel memory by leveraging the absence of a certain orphaning operation. NOTE: the affected code was moved to the skb_zerocopy function in net/core/skbuff.c before the vulnerability was announced.

Impact & exploitability

Attack vectorAdjacent
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impactNone
Availability impactNone
Exploit probability (EPSS)1%

AV:A/AC:M/Au:N/C:P/I:N/A:N

Affected products we track (1)

Recommendation

Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.

Official patch: http://www.openwall.com/lists/oss-security/2014/03/20/16 ↗