CVE-2018-14634

Advisory lineage Upstream: 0 Downstream: 23
Analyzed
Published: 25 Sept 2018, 21:00
Last modified:27 Jan 2026, 13:34

Vulnerability Summary

Overall Risk (default)
medium
45/100
CVSS Score
7.8 HIGH
v3.0 (cve.org)
EPSS Score
20.57% HIGH
21% probability +1.08%
KEV
Listed
CISA
1 listing
Ransomware
No reports
Public exploits
2 found
Dark Web
Not detected

Timeline

25 Sept 2018, 21:00
Published
Vulnerability first disclosed
26 Jan 2026, 00:00
Added to CISA KEV
Linux Kernel Integer Overflow Vulnerability
27 Jan 2026, 13:34
Last Modified
Vulnerability information updated
16 Feb 2026, 00:00
CISA Remediation Due
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

Description

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.

CVSS Metrics

  • v3.0HIGHScore: 7.8CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • v2.0HIGHScore: 7.2AV:L/AC:L/Au:N/C:C/I:C/A:C

EPSS Trends

Current EPSS score: 20.57% Percentile: 96%

Techniques & Countermeasures

  • CWE-190Integer Overflow or Wraparound

    The product performs a calculation that can produce an integer overflow or wraparound when the logic assumes that the resulting value will always be larger than the original value. This occurs when an integer value is incremented to a value that is too large to store in the associated representation. When this occurs, the value may become a very small or negative number.

Affected Systems

  • canonicalubuntu_linux

    12.04 | 14.04

  • f5big-ip_access_policy_manager

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-ip_advanced_firewall_manager

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-ip_analytics

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-ip_application_acceleration_manager

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-ip_application_security_manager

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-ip_domain_name_system

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-ip_edge_gateway

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-ip_fraud_protection_service

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-ip_global_traffic_manager

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-ip_link_controller

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-ip_local_traffic_manager

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-ip_policy_enforcement_manager

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-ip_webaccelerator

    ≥ 11.2.1, < 11.6.4 | ≥ 12.1.0, < 12.1.5 | ≥ 13.0.0, < 13.1.1.5 | ≥ 14.0.0, < 14.0.1.1 | ≥ 14.1.0, < 14.1.0.6

  • f5big-iq_centralized_management

    ≥ 5.0.0, ≤ 5.4.0 | ≥ 6.0.0, ≤ 6.0.1 | ≥ 7.0.0, ≤ 7.1.0 | 4.6.0

  • f5big-iq_cloud_and_orchestration

    1.0.0

  • f5enterprise_manager

    3.1.1

  • f5iworkflow

    ≥ 2.2.0, ≤ 2.3.0

  • f5traffix_signaling_delivery_controller

    ≥ 5.0.0, ≤ 5.1.0 | 4.4.0

  • linuxlinux_kernel

    ≥ 2.6.0, ≤ 2.6.39.4 | ≥ 3.10, ≤ 3.10.102 | ≥ 4.14, ≤ 4.14.54

  • netappsnapprotect

    na

  • paloaltonetworkspan-os

    ≥ 7.1.0, < 7.1.23 | ≥ 8.0.0, < 8.0.16 | ≥ 8.1.0, < 8.1.7

  • redhatenterprise_linux_desktop

    6.0 | 7.0

  • redhatenterprise_linux_server

    6.0 | 7.0

  • redhatenterprise_linux_server_aus

    6.5 | 6.6 | 7.6

  • redhatenterprise_linux_server_eus

    6.7 | 7.5 | 7.6

  • redhatenterprise_linux_server_tus

    6.6 | 7.6

  • redhatenterprise_linux_workstation

    6.0 | 7.0

  • the linux foundationkernel

    2.6.x, 3.10.x, 4.14.x

References (23)