VYPR
Unrated severityNVD Advisory· Published Jan 18, 2014· Updated Jun 17, 2026

CVE-2014-1444

CVE-2014-1444

Description

The fst_get_iface function in drivers/net/wan/farsync.c in the Linux kernel before 3.11.7 does not properly initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging the CAP_NET_ADMIN capability for an SIOCWANDEV ioctl call.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

8
  • Linux/Kernel7 versions
    cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*+ 6 more
    • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*range: <=3.11.6
    • cpe:2.3:o:linux:linux_kernel:3.11:*:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:3.11.1:*:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:3.11.2:*:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:3.11.3:*:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:3.11.4:*:*:*:*:*:*:*
    • cpe:2.3:o:linux:linux_kernel:3.11.5:*:*:*:*:*:*:*
  • Range: < 3.11.7

Patches

Vulnerability mechanics

References

9

News mentions

0

No linked articles in our index yet.