<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Thu, 08 Oct 2026 01:30:32 +0000</lastBuildDate>
    <item>
      <title>CVE-2014-4014</title>
      <link>https://cve.radiocsirt.org/vuln/cve-2014-4014</link>
      <description>&lt;p&gt;The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/cve-2014-4014</guid>
    </item>
    <item>
      <title>USN-2337-1 — linux vulnerabilities</title>
      <link>https://cve.radiocsirt.org/vuln/usn-2337-1</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: linux&lt;/p&gt;
&lt;p&gt;A flaw was discovered in the Linux kernel virtual machine&amp;#39;s (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)&lt;/p&gt;
&lt;p&gt;Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)&lt;/p&gt;
&lt;p&gt;An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-2014-0206)&lt;/p&gt;
&lt;p&gt;A flaw was discovered in the Linux kernel&amp;#39;s implementation of user
namespaces with respect to inode permissions. A local user could exploit
this flaw by creating a user namespace to gain administrative privileges.
(CVE-2014-4014)&lt;/p&gt;
&lt;p&gt;An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)&lt;/p&gt;
&lt;p&gt;Sasha Levin reported an issue with the Linux kernel&amp;#39;s shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause a denial of service. (CVE-2014-4171)&lt;/p&gt;
&lt;p&gt;Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit…&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; Ubuntu:14.04:LTS: linux&lt;/p&gt;
&lt;p&gt;A flaw was discovered in the Linux kernel virtual machine&amp;#39;s (kvm)
validation of interrupt requests (irq). A guest OS user could exploit this
flaw to cause a denial of service (host OS crash). (CVE-2014-0155)&lt;/p&gt;
&lt;p&gt;Andy Lutomirski discovered a flaw in the authorization of netlink socket
operations when a socket is passed to a process of more privilege. A local
user could exploit this flaw to bypass access restrictions by having a
privileged executable do something it was not intended to do.
(CVE-2014-0181)&lt;/p&gt;
&lt;p&gt;An information leak was discovered in the Linux kernels
aio_read_events_ring function. A local user could exploit this flaw to
obtain potentially sensitive information from kernel memory.
(CVE-2014-0206)&lt;/p&gt;
&lt;p&gt;A flaw was discovered in the Linux kernel&amp;#39;s implementation of user
namespaces with respect to inode permissions. A local user could exploit
this flaw by creating a user namespace to gain administrative privileges.
(CVE-2014-4014)&lt;/p&gt;
&lt;p&gt;An information leak was discovered in the rd_mcp backend of the iSCSI
target subsystem in the Linux kernel. A local user could exploit this flaw
to obtain sensitive information from ramdisk_mcp memory by leveraging
access to a SCSI initiator. (CVE-2014-4027)&lt;/p&gt;
&lt;p&gt;Sasha Levin reported an issue with the Linux kernel&amp;#39;s shared memory
subsystem when used with range notifications and hole punching. A local
user could exploit this flaw to cause a denial of service. (CVE-2014-4171)&lt;/p&gt;
&lt;p&gt;Toralf Förster reported an error in the Linux kernels syscall auditing on
32 bit…&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/usn-2337-1</guid>
    </item>
  </channel>
</rss>
