Vulnerability Intelligence Report
Linux Kernel Integer Overflow Vulnerability
CVE-2018-14634
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
7.8
HIGH
Exploitability:1.9
Impact Score:5.9
EPSS Probability:14.81%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-190 ↗CWE-190
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| The Linux Foundation | kernel | 2.6.x, 3.10.x, 4.14.x (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Red Hat, Inc. · Vendor · USA |
| Reserved | 2018-07-27T00:00:00 |
| Published | 2018-09-25T21:00:00 |
| Patch Date | 2018-09-25 |
| Last Updated | 2026-01-27T13:34:52 |
Community Chatter & Buzz