Vulnerability record · CVE-2018-14634 · published 25 September 2018
CVE-2018-14634: Linux kernel create_elf_tables() integer overflow privilege escalation
Paloaltonetworks · Pan Os
An integer overflow in the Linux kernel's create_elf_tables() function lets an unprivileged local user escalate privileges when a SUID or otherwise privileged binary is present. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable, and the flaw affects the kernel as shipped in multiple vendor products. Because it yields full root-level compromise from a low-privilege local account, it is a serious post-access escalation path.
Description
An integer overflow flaw was found in the Linux kernel's create_elf_tables() function. An unprivileged local user with access to SUID (or otherwise privileged) binary could use this flaw to escalate their privileges on the system. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityLocal privilege escalation to root with public exploit code and KEV listing, but it requires an existing unprivileged account and a SUID binary, so it is not remotely exploitable.
What it is
An integer overflow in the Linux kernel's create_elf_tables() function lets an unprivileged local user escalate privileges when a SUID or otherwise privileged binary is present. Kernel versions 2.6.x, 3.10.x and 4.14.x are believed to be vulnerable, and the flaw affects the kernel as shipped in multiple vendor products. Because it yields full root-level compromise from a low-privilege local account, it is a serious post-access escalation path.
Impact
An attacker with a local unprivileged account gains full control of the host, including confidentiality, integrity and availability of all data and processes. This turns any low-privilege foothold into complete system compromise.
Attack surface
Reached locally: the CVSS vector is AV:L/PR:L/UI:N, so the attacker needs an existing unprivileged account and no user interaction. A SUID or otherwise privileged binary must be present on the system for the escalation to succeed.
Exploitation
CISA added this to KEV on 2026-01-26 with a remediation due date of 2026-02-16, and EPSS gives a 30-day probability of 0.14689 (96th percentile). Public exploit code is referenced (Exploit-DB 45516 and an oss-security post tagged Exploit), though no ransomware campaign use is documented.
What to do
- Patch the Linux kernel to a vendor-fixed release; apply the Red Hat, Ubuntu, F5, NetApp and Palo Alto advisories listed in the references.
- If patching is not immediately possible, follow vendor mitigation instructions and BOD 22-01 guidance for cloud services, or discontinue use of the affected product.
- Reduce the number of SUID/privileged binaries on hosts and remove those not strictly required, since the flaw needs one to be present.
- Restrict and monitor local interactive access so unprivileged accounts are limited to trusted users.
- Track KEV remediation deadlines (due 2026-02-16) and confirm affected appliances and kernels are covered.
Detection
- Audit hosts for unpatched kernel versions in the 2.6.x, 3.10.x and 4.14.x lines and for vendor products listed as affected.
- Monitor for unexpected privilege transitions to root by non-root accounts, especially processes spawned from SUID binaries.
- Alert on execution of known public exploit code or suspicious ELF argument manipulation against privileged binaries.
- Review local account creation and login activity for signs of an unprivileged foothold being used to attempt escalation.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2018-14634 to the Known Exploited Vulnerabilities catalog on 26 January 2026 as "Linux Kernel Integer Overflow Vulnerability". Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. Federal deadline 16 February 2026.
Affected products
28 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2018-14634 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2018-14634), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.