ZeroHour

CVE-2018-14634

KEV PoC ×2mass

Linux Kernel create_elf_tables() Integer Overflow Local Privilege Escalation

CISA: Linux Kernel Integer Overflow Vulnerability

CVSS 3.0
7.8 high
EPSS
15%p96
Published
()
KEV added
AI analysis

CVE-2018-14634 is an integer overflow in the Linux kernel's create_elf_tables() function, the code that builds the ELF auxiliary tables when a new program is launched. An unprivileged local user can trigger the overflow by executing a SUID or otherwise privileged binary, corrupting kernel memory and escalating their privileges. A successful attacker gains full root-level control of the affected host, compromising the confidentiality, integrity, and availability of that system. Any system running a Linux kernel in the 2.6.x, 3.10.x, or 4.14.x series is affected, including products from Red Hat, Canonical, Palo Alto Networks (PAN-OS), F5 (BIG-IP), and NetApp that ship those kernels. CISA added this flaw to its Known Exploited Vulnerabilities catalog on 2026-01-26, confirming it is being actively exploited, and EPSS estimates a 14.7% chance of exploitation within 30 days (96th percentile).

What to do: Apply the kernel updates published by Red Hat, Canonical, and other distributors and upgrade affected appliances (PAN-OS and BIG-IP) to the patched releases cited in each vendor's advisory for CVE-2018-14634, per the CISA KEV required action. Inventory hosts and appliances running Linux kernels in the 2.6.x, 3.10.x, or 4.14.x series and verify patched versions are installed. Because this is a local privilege escalation with no network-level mitigation, restrict unprivileged local accounts and limit access to SUID binaries on hosts where patching is delayed.

Affected
Linux Kernel2.6.x, 3.10.x, and 4.14.x series (believed to be vulnerable per the advisory)
Red Hat Enterprise Linux (affected kernel series)kernels in the 2.6.x/3.10.x series; specific package fix levels not specified in source data
Canonical Ubuntu (affected kernel series)
Palo Alto Networks PAN-OS
F5 BIG-IP Local Traffic Manager, Global Traffic Manager, Link Controller, DNS, Access Policy Manager, Application Security
NetApp products shipping affected Linux kernels
Estimated exposure
massseveral million servers and network appliances ran vulnerable kernels when the flaw was disclosed; the remaining unpatched population today is likely in the… — The affected kernel series shipped in the very large Red Hat/Ubuntu enterprise installed base and inside widely deployed PAN-OS firewalls and F5 BIG-IP appliances (public internet-exposure scans regularly find on the order of 100k+ devices…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.

CISA Known Exploited Vulnerability
Affected
Linux Kernel
Required action
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
paloaltonetworksf5linuxredhatcanonicalnetapp
Products
pan-os, big-ip access policy manager, big-ip advanced firewall manager, big-ip analytics, big-ip application acceleration manager, big-ip application security manager, big-ip domain name system, big-ip edge gateway, big-ip fraud protection service, big-ip global traffic manager, big-ip link controller, big-ip local traffic manager
Weakness
CWE-190
Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news