← Vulnerability feed

Vulnerability record · CVE-2018-14634 · published 25 September 2018

CVE-2018-14634: Linux kernel create_elf_tables() integer overflow privilege escalation

Paloaltonetworks · Pan Os

An integer overflow in the Linux kernel's create_elf_tables() function lets an unprivileged local user escalate privileges when a SUID or otherwise privileged binary is present. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable, and the flaw affects the kernel as shipped in multiple vendor products. Because it yields full root-level compromise from a low-privilege local account, it is a serious post-access escalation path.

7.8 CVSS 3.0 High CISA KEV since 26 Jan 2026 EPSS 15% · top 3.4% CWE-190 · Integer overflow
7.8CVSS 3.0 base score, v2 7.2
15%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
28Affected product versions listed by NVD
45References, 4 tagged exploit
17 Jun 2026Last modified by NVD

Description

An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityLocal privilege escalation to root with public exploit code and KEV listing, but it requires an existing unprivileged account and a SUID binary, so it is not remotely exploitable.

What it is

An integer overflow in the Linux kernel's create_elf_tables() function lets an unprivileged local user escalate privileges when a SUID or otherwise privileged binary is present. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable, and the flaw affects the kernel as shipped in multiple vendor products. Because it yields full root-level compromise from a low-privilege local account, it is a serious post-access escalation path.

Impact

An attacker with a local unprivileged account gains full control of the host, including confidentiality, integrity and availability of all data and processes. This turns any low-privilege foothold into complete system compromise.

Attack surface

Reached locally: the CVSS vector is AV:L/PR:L/UI:N, so the attacker needs an existing unprivileged account and no user interaction. A SUID or otherwise privileged binary must be present on the system for the escalation to succeed.

Exploitation

CISA added this to KEV on 2026-01-26 with a remediation due date of 2026-02-16, and EPSS gives a 30-day probability of 0.14689 (96th percentile). Public exploit code is referenced (Exploit-DB 45516 and an oss-security post tagged Exploit), though no ransomware campaign use is documented.

What to do

  • Patch the Linux kernel to a vendor-fixed release; apply the Red Hat, Ubuntu, F5, NetApp and Palo Alto advisories listed in the references.
  • If patching is not immediately possible, follow vendor mitigation instructions and BOD 22-01 guidance for cloud services, or discontinue use of the affected product.
  • Reduce the number of SUID/privileged binaries on hosts and remove those not strictly required, since the flaw needs one to be present.
  • Restrict and monitor local interactive access so unprivileged accounts are limited to trusted users.
  • Track KEV remediation deadlines (due 2026-02-16) and confirm affected appliances and kernels are covered.

Detection

  • Audit hosts for unpatched kernel versions in the 2.6.x, 3.10.x and 4.14.x lines and for vendor products listed as affected.
  • Monitor for unexpected privilege transitions to root by non-root accounts, especially processes spawned from SUID binaries.
  • Alert on execution of known public exploit code or suspicious ELF argument manipulation against privileged binaries.
  • Review local account creation and login activity for signs of an unprivileged foothold being used to attempt escalation.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2018-14634 to the Known Exploited Vulnerabilities catalog on 26 January 2026 as "Linux Kernel Integer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 February 2026.

Affected products

28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://www.openwall.com/lists/oss-security/2021/07/20/2 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/105407 Broken LinkThird Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2018:2748 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2763 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2846 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2924 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2925 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2933 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3540 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3586 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3590 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3591 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3643 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14634 Issue TrackingThird Party Advisory
https://security.netapp.com/advisory/ntap-20190204-0002/ PatchThird Party Advisory
https://security.paloaltonetworks.com/CVE-2018-14634 Third Party Advisory
https://support.f5.com/csp/article/K20934447?utm_source=f5support&amp%3Butm_medium=RSS Third Party Advisory
https://usn.ubuntu.com/3775-1/ Third Party Advisory
https://usn.ubuntu.com/3775-2/ Third Party Advisory
https://usn.ubuntu.com/3779-1/ Third Party Advisory
https://www.exploit-db.com/exploits/45516/ ExploitThird Party AdvisoryVDB Entry
https://www.openwall.com/lists/oss-security/2018/09/25/4 ExploitMailing ListThird Party Advisory
http://www.openwall.com/lists/oss-security/2021/07/20/2 Mailing ListThird Party Advisory
http://www.securityfocus.com/bid/105407 Broken LinkThird Party AdvisoryVDB Entry
https://access.redhat.com/errata/RHSA-2018:2748 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2763 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2846 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2924 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2925 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:2933 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3540 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3586 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3590 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3591 Third Party Advisory
https://access.redhat.com/errata/RHSA-2018:3643 Third Party Advisory
https://bugzilla.redhat.com/show_bug.cgi?id=CVE-2018-14634 Issue TrackingThird Party Advisory
https://security.netapp.com/advisory/ntap-20190204-0002/ PatchThird Party Advisory
https://security.paloaltonetworks.com/CVE-2018-14634 Third Party Advisory
https://support.f5.com/csp/article/K20934447?utm_source=f5support&amp%3Butm_medium=RSS Third Party Advisory
https://usn.ubuntu.com/3775-1/ Third Party Advisory

Track CVE-2018-14634 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-46747F5 BIG-IP configuration utility authentication bypass allows command executionUndisclosed requests can bypass authentication in the BIG-IP configuration utility, letting a network-positioned attacker execute arbitrary system co…KEVEPSS 97%analysed9.8CVE-2022-1388F5 BIG-IP iControl REST authentication bypassUndisclosed requests to the iControl REST interface on multiple F5 BIG-IP modules can bypass authentication, allowing an unauthenticated remote attac…KEVEPSS 100%analysed9.8CVE-2021-22991F5 BIG-IP TMM URI normalization buffer overflowF5 BIG-IP's Traffic Management Microkernel (TMM) mishandles URI normalization for undisclosed requests to a virtual server, triggering a buffer overf…KEVEPSS 61%analysed9.8CVE-2021-22986F5 BIG-IP iControl REST unauthenticated remote command executionThe iControl REST interface on multiple F5 BIG-IP and BIG-IQ versions exposes an unauthenticated remote command execution flaw, tracked as CWE-918 se…KEVEPSS 100%analysed9.8CVE-2020-5902F5 BIG-IP TMUI path traversal leading to remote code executionThe F5 BIG-IP Traffic Management User Interface (TMUI, also called the Configuration utility) contains a path traversal flaw (CWE-22) in undisclosed …KEVEPSS 100%analysed9.8CVE-2020-11651SaltStack Salt master authentication bypass in ClearFuncsSaltStack Salt before 2019.2.4 and 3000 before 3000.2 fails to properly validate method calls in the salt-master ClearFuncs class, allowing remote un…KEVEPSS 97%analysed9.8CVE-2020-7247OpenSMTPD MAIL FROM command injection allows remote root code executionOpenSMTPD 6.6, as shipped in OpenBSD 6.6 and other products, mishandles input validation in smtp_mailaddr in smtp_session.c, returning an incorrect v…KEVEPSS 99%analysed9.8CVE-2019-11043PHP-FPM buffer overflow enables remote code executionPHP-FPM in certain configurations writes past allocated buffers into FCGI protocol data space, an out-of-bounds write (CWE-787, CWE-120). It affects …KEVEPSS 100%analysed

Source: NIST National Vulnerability Database (record CVE-2018-14634), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.