{
  "id": "CVE-2014-0196",
  "url": "https://spydr.io/cve/CVE-2014-0196",
  "published": "2014-05-07T10:55:04.337Z",
  "modified": "2026-06-17T00:02:29.250Z",
  "score": 5.5,
  "severity": "medium",
  "cvss_version": "3.1",
  "vector": "CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H",
  "score_source": "CISA ADP",
  "epss": 0.22475,
  "epss_percentile": 0.97653,
  "exploited": true,
  "kev": {
    "added": "2023-05-12",
    "due": "2023-06-02",
    "action": "The impacted product is end-of-life and should be disconnected if still in use.",
    "ransomware": "Unknown",
    "name": "Linux Kernel Race Condition Vulnerability",
    "notes": "https://lkml.iu.edu/hypermail/linux/kernel/1609.1/02103.html; https://nvd.nist.gov/vuln/detail/CVE-2014-0196"
  },
  "ssvc_exploitation": "active",
  "vendors": [
    "linux",
    "debian",
    "redhat",
    "suse",
    "oracle",
    "canonical",
    "f5"
  ],
  "products": [
    "linux kernel",
    "debian linux",
    "redhat enterprise linux",
    "redhat enterprise linux eus",
    "redhat enterprise linux server eus",
    "suse linux enterprise desktop",
    "suse linux enterprise high availability extension",
    "suse linux enterprise server",
    "oracle linux",
    "canonical ubuntu linux",
    "f5 big-ip access policy manager",
    "f5 big-ip advanced firewall manager",
    "f5 big-ip analytics",
    "f5 big-ip application acceleration manager",
    "f5 big-ip application security manager",
    "f5 big-ip edge gateway",
    "f5 big-ip global traffic manager",
    "f5 big-ip link controller",
    "f5 big-ip local traffic manager",
    "f5 big-ip policy enforcement manager"
  ],
  "cwes": [
    "CWE-362"
  ],
  "description": "The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the \"LECHO & !OPOST\" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.",
  "status": "Analyzed",
  "score_type": "Secondary",
  "scores": {
    "cvss_v40": null,
    "cvss_v31": 5.5,
    "cvss_v30": null
  },
  "references": [
    {
      "url": "http://bugzilla.novell.com/show_bug.cgi?id=875690",
      "tags": [
        "Issue Tracking",
        "Permissions Required",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=4291086b1f081b869c6d79e5b7441633dc3ace00",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://linux.oracle.com/errata/ELSA-2014-0771.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00007.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00012.html",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://pastebin.com/raw.php?i=yTSFUBgZ",
      "tags": [
        "Exploit",
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://rhn.redhat.com/errata/RHSA-2014-0512.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://secunia.com/advisories/59218",
      "tags": [
        "Not Applicable"
      ]
    },
    {
      "url": "http://secunia.com/advisories/59262",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://secunia.com/advisories/59599",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://source.android.com/security/bulletin/2016-07-01.html",
      "tags": [
        "Not Applicable"
      ]
    },
    {
      "url": "http://support.f5.com/kb/en-us/solutions/public/15000/300/sol15319.html",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.debian.org/security/2014/dsa-2926",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.debian.org/security/2014/dsa-2928",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.exploit-db.com/exploits/33516",
      "tags": [
        "Exploit",
        "Third Party Advisory",
        "VDB Entry"
      ]
    },
    {
      "url": "http://www.openwall.com/lists/oss-security/2014/05/05/6",
      "tags": [
        "Mailing List",
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.osvdb.org/106646",
      "tags": [
        "Broken Link"
      ]
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2196-1",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2197-1",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2198-1",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2199-1",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2200-1",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2201-1",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2202-1",
      "tags": [
        "Third Party Advisory"
      ]
    },
    {
      "url": "http://www.ubuntu.com/usn/USN-2203-1",
      "tags": [
        "Third Party Advisory"
      ]
    }
  ],
  "nvd_url": "https://nvd.nist.gov/vuln/detail/CVE-2014-0196",
  "covered_in": [],
  "attribution": [
    {
      "source": "NVD",
      "url": "https://nvd.nist.gov",
      "notice": "This product uses data from the NVD API but is not endorsed or certified by the NVD."
    },
    {
      "source": "CISA KEV",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "notice": "Known exploited vulnerabilities from the CISA KEV catalog."
    },
    {
      "source": "FIRST EPSS",
      "url": "https://www.first.org/epss",
      "notice": "Exploit prediction scores from FIRST EPSS."
    }
  ]
}
