Evidence dossier

CVE-2014-0196

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local…

Exploited in the wild (CISA KEV since May 12, 2023). NVD reports CVSS 2.0 6.9. EPSS estimates 22.5% exploit likelihood as of Aug 27, 2026.

77.677.8Priority evidence range
Evidence current through Aug 27, 2026, 6:09 PM UTC

As of Aug 27, 2026

Normalized restatement

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

State
PUBLISHED
Published
May 7, 2014
Updated
Oct 22, 2025
Evidence coverage
99%

Evidence chronology

What was known when

Download this view's receipt →
  1. Source dateSource date omittedFirst observed by CASCA
    CISA-ADP

    Record text: CISA ADP Vulnrichment

    Inspect raw assertion
    Field
    container
    Value
    CISA ADP Vulnrichment
    Original evidence ↗
  2. Source dateSource date omittedFirst observed by CASCA
    CVE Program

    Record text: CVE Program Container

    Inspect raw assertion
    Field
    container
    Value
    CVE Program Container
    Original evidence ↗
  3. Source dateSource date omittedFirst observed by CASCA
    redhat

    Record text: The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

    Inspect raw assertion
    Field
    container
    Value
    The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
    Original evidence ↗
  4. Source dateFirst observed by CASCA
    CISA KEV

    Exploitation cataloged: Linux Kernel Race Condition Vulnerability

    Inspect raw assertion
    Field
    observed_exploitation
    Value
    Linux Kernel Race Condition Vulnerability
    Original evidence ↗
  5. Source dateFirst observed by CASCA
    FIRST EPSS

    EPSS score: 22.48% probability · 97.53th percentile

    Inspect raw assertion
    Field
    model_probability
    Value
    Probability 0.224750000000; percentile 0.975280000000
    Original evidence ↗
ExploitationCatalog member

CISA KEV · catalog date May 12, 2023 · first observed Jul 19, 2026

Exploit likelihood22.48%

FIRST EPSS · score date Aug 27, 2026 · 97.5th percentile · first observed Aug 27, 2026

SeverityCVSS 6.9

NVD · CVSS 2.0 · first observed Jul 19, 2026 · same-version scores align in this snapshot

Evidence detail

Source limits and decisions

Why each evidence state has this value

casca-unknown-reasons-v1
Exploitation statusEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Exploit likelihoodEvidence supported

Eligible evidence is present for this bounded claim.

Revision
evidence-policy-v1.1.0
Cutoff
Aug 27, 2026
Resolution
None
Severity assessmentEvidence supported

Eligible evidence is present for this bounded claim.

Revision
casca-direct-cvss-eligibility-v1
Cutoff
Aug 27, 2026
Resolution
None
Affected productsSource-reported scope

The cited source assertion is retained while canonical product linkage remains open.

Revision
casca-factor-d-obligations-v1
Cutoff
Aug 27, 2026
Resolution
Resolve identity

Source comparison

Who said what

CISA-ADPIndependent enrichment
Record text

CISA ADP Vulnrichment

Inspect raw assertion
Field
container
Value
CISA ADP Vulnrichment
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CVE ProgramDerivative copy
Record text

CVE Program Container

Inspect raw assertion
Field
container
Value
CVE Program Container
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
redhatOriginal assertion
Record text

The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.

Inspect raw assertion
Field
container
Value
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
Source dateSource date omittedFirst observed by CASCAOriginal evidence ↗
CISA KEVOriginal assertion
Exploitation cataloged

Linux Kernel Race Condition Vulnerability

Inspect raw assertion
Field
observed_exploitation
Value
Linux Kernel Race Condition Vulnerability
Source dateFirst observed by CASCAOriginal evidence ↗
FIRST EPSSOriginal assertion
EPSS score

22.48% probability · 97.53th percentile

Inspect raw assertion
Field
model_probability
Value
Probability 0.224750000000; percentile 0.975280000000
Source dateFirst observed by CASCAOriginal evidence ↗

Applicability

Cited product scope

Trace impact →
50Underlying assertions
30Canonical products
50Target assertions
0Constraint assertions

Grouped from 7 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.

Identity source boundaries
  • Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z27d65b0f-b718-4b4f-bb79-c47c68d09dfa
  • Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z955dae73-7302-438b-aee1-058d7cc5d48e

31 scope groups

redhat · source assertedn/an/aDirect source scope
Affected: n/a
Source-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Inspect raw assertion[{"status": "affected", "version": "n/a"}]
NVD CPE · OPERATING SYSTEMcanonicalubuntu_linuxVulnerable target · 5 assertions
Version 10.04; Version 12.04; Version 12.10; Version 13.10; Version 14.04Canonical identity product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    8d305f7a-d159-4716-ab26-5e38bb5cd991
  2. cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 4
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    815d70a8-47d3-459c-a32c-9feaca0659d1
  3. cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 2
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e2076871-2e80-4605-a470-a41c1a8ec7ee
  4. cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    01eda41c-6b2e-49af-b503-eb3882265c11
  5. cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    5 · node/0 · match 3
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    7f61f047-129c-41a6-8a27-ffcbb8563e91
NVD CPE · OPERATING SYSTEMdebiandebian_linuxVulnerable target · 2 assertions
Version 6.0; Version 7.0Canonical identity product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 1
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    16f59a04-14cf-49e2-9973-645477ea09da
  2. cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    1 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    036e8a89-7a16-411f-9d31-676313bb7244
NVD CPE · APPLICATIONf5big-ip_access_policy_managerVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.1.0, <= 11.5.1)Canonical identity product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cbLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 0
    Logic
    OR
    Version bounds
    from including 11.1.0; through including 11.5.1
    Match ID
    8f315708-017c-4362-9c09-6774f89d9370
NVD CPE · APPLICATIONf5big-ip_advanced_firewall_managerVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.3.0, <= 11.5.1)Canonical identity product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 11.3.0; through including 11.5.1
    Match ID
    48bbef73-e87d-467f-85eb-47be212df0e8
NVD CPE · APPLICATIONf5big-ip_analyticsVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.1.0, <= 11.5.1)Canonical identity product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943fLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 11.1.0; through including 11.5.1
    Match ID
    a430ffb4-418c-43da-8e17-020618a77a56
NVD CPE · APPLICATIONf5big-ip_application_acceleration_managerVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.4.0, <= 11.5.1)Canonical identity product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 11.4.0; through including 11.5.1
    Match ID
    c483253f-841e-4d4e-9b4a-932e9d07268b
NVD CPE · APPLICATIONf5big-ip_application_security_managerVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.1.0, <= 11.5.1)Canonical identity product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803daLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 11.1.0; through including 11.5.1
    Match ID
    7a0cc74c-6914-4a6f-a1ce-65a695ae31f6
NVD CPE · APPLICATIONf5big-ip_edge_gatewayVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.1.0, <= 11.3.0)Canonical identity product-2ef3e3330ef867854f3e55800c0e0cdd023371aa73dd9e7add7dfa128e66c26aLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 5
    Logic
    OR
    Version bounds
    from including 11.1.0; through including 11.3.0
    Match ID
    9ff30167-0241-4136-82f8-2d2fb545c19a
NVD CPE · APPLICATIONf5big-ip_global_traffic_managerVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.1.0, <= 11.5.1)Canonical identity product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 6
    Logic
    OR
    Version bounds
    from including 11.1.0; through including 11.5.1
    Match ID
    54a45725-fecd-4ca9-bfa4-e13fcdfddf13
NVD CPE · APPLICATIONf5big-ip_link_controllerVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.1.0, <= 11.5.1)Canonical identity product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dabLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 7
    Logic
    OR
    Version bounds
    from including 11.1.0; through including 11.5.1
    Match ID
    8c596b3f-9d93-49d2-99d7-d590cc9aeaa5
NVD CPE · APPLICATIONf5big-ip_local_traffic_managerVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.1.0, <= 11.5.1)Canonical identity product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 8
    Logic
    OR
    Version bounds
    from including 11.1.0; through including 11.5.1
    Match ID
    d8696a6b-1b56-43b5-a506-21e17735b9ca
NVD CPE · APPLICATIONf5big-ip_policy_enforcement_managerVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.3.0, <= 11.5.1)Canonical identity product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 9
    Logic
    OR
    Version bounds
    from including 11.3.0; through including 11.5.1
    Match ID
    e9a06d61-e6cb-4a8a-b06d-9fea1812c167
NVD CPE · APPLICATIONf5big-ip_protocol_security_moduleVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.1.0, <= 11.4.1)Canonical identity product-c292d03866ff8f16359315a2e8a89dcc4f7e5d70bc08cbce1625d4ee2032777aLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 10
    Logic
    OR
    Version bounds
    from including 11.1.0; through including 11.4.1
    Match ID
    8c666a18-9ded-4b49-92de-474403fc17bf
NVD CPE · APPLICATIONf5big-ip_wan_optimization_managerVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.1.0, <= 11.3.0)Canonical identity product-da9ac0561bce1fb3f2be50345c74276dffd0904067ef9858397b76a9fb869f4cLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_wan_optimization_manager:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 11
    Logic
    OR
    Version bounds
    from including 11.1.0; through including 11.3.0
    Match ID
    a6b52d60-38db-4be9-91f4-b6553f5e5a93
NVD CPE · APPLICATIONf5big-ip_webacceleratorVulnerable target · 1 assertions
Any version (unconstrained) (>= 11.1.0, <= 11.3.0)Canonical identity product-9a98c46bb3d6ba9611bd32eab93edabd599af91bf31121c045dc220d5c65e47bLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 12
    Logic
    OR
    Version bounds
    from including 11.1.0; through including 11.3.0
    Match ID
    e1e3204f-9464-4ac3-819b-d1a6b399fae3
NVD CPE · APPLICATIONf5big-iq_application_delivery_controllerVulnerable target · 1 assertions
Version 4.5.0Canonical identity product-1328f0fc37701e8fa6b4c8e4957cb3081d1e02cff26e2087bb4ce6b905d5da60Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-iq_application_delivery_controller:4.5.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 13
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    222b4de7-1d3d-40df-a9eb-efabda8faea6
NVD CPE · APPLICATIONf5big-iq_centralized_managementVulnerable target · 1 assertions
Version 4.6.0Canonical identity product-c606d5370e1ae0f499fdbd5035f77ca02d8a84a54acabd597edb41f7a7690295Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-iq_centralized_management:4.6.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 14
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    24aef0b2-7c8c-432c-a840-c2441a70343f
NVD CPE · APPLICATIONf5big-iq_cloudVulnerable target · 1 assertions
Any version (unconstrained) (>= 4.0.0, <= 4.5.0)Canonical identity product-b8aa0349e7204b53f4ad3e4f173c83d7535e55b4e37cfc14d47a2aed72c1a867Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-iq_cloud:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 15
    Logic
    OR
    Version bounds
    from including 4.0.0; through including 4.5.0
    Match ID
    8c8bf865-ba45-4711-829f-ec8e5ea22d2f
NVD CPE · APPLICATIONf5big-iq_cloud_and_orchestrationVulnerable target · 1 assertions
Version 1.0.0Canonical identity product-1034b13a364737235c88557ca41a25f206ac20c0fab2a19375ad42f5bbd94b3cLinked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-iq_cloud_and_orchestration:1.0.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 16
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    e21d6206-4716-47fe-a733-f18343656e94
NVD CPE · APPLICATIONf5big-iq_deviceVulnerable target · 1 assertions
Any version (unconstrained) (>= 4.2.0, <= 4.5.0)Canonical identity product-64a87e2f5b8db7cf37895c491723c860754a6486575c5ac3cbbe3d7cf58a3478Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-iq_device:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 17
    Logic
    OR
    Version bounds
    from including 4.2.0; through including 4.5.0
    Match ID
    3bc0eafd-da5e-4a1b-81cb-0d5a964f9eb6
NVD CPE · APPLICATIONf5big-iq_securityVulnerable target · 1 assertions
Any version (unconstrained) (>= 4.0.0, <= 4.5.0)Canonical identity product-1bf32c16a3b62f96b746809fb185242f3cb6ddf0e8a05e63872d6eec958472d6Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:a:f5:big-iq_security:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 18
    Logic
    OR
    Version bounds
    from including 4.0.0; through including 4.5.0
    Match ID
    6b3e56eb-202a-4f58-8e94-b2dda1693498
NVD CPE · APPLICATIONf5enterprise_managerVulnerable target · 2 assertions
Version 3.1.0; Version 3.1.1Canonical identity product-006eb8e0173436b9e5f2c74987109b01caa48599f0370351c5c62638221385d0Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:a:f5:enterprise_manager:3.1.0:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 19
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4c580f19-af18-49ee-89ff-8c4f5c88314d
  2. cpe:2.3:a:f5:enterprise_manager:3.1.1:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    6 · node/0 · match 20
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d5f5fee7-059a-4a9b-bccd-18f0aa435040
NVD CPE · OPERATING SYSTEMlinuxlinux_kernelVulnerable target · 13 assertions
Any version (unconstrained) (> 2.6.31, < 3.2.59); Any version (unconstrained) (>= 3.11, < 3.12.20); Any version (unconstrained) (>= 3.13, < 3.14.4); Any version (unconstrained) (>= 3.3, < 3.4.91); Any version (unconstrained) (>= 3.5, < 3.10.40); Version 2.6.31Canonical identity product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9Linked exact
Scope supported
Inspect raw assertions
  1. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 2
    Logic
    OR
    Version bounds
    from including 3.5; through excluding 3.10.40
    Match ID
    287dc65b-a513-4fb9-a1cf-69f428030df8
  2. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 3
    Logic
    OR
    Version bounds
    from including 3.11; through excluding 3.12.20
    Match ID
    d82f8c94-5fa7-4a7a-8855-ecf21b3bbd42
  3. cpe:2.3:o:linux:linux_kernel:2.6.31:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 5
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    2887290a-1b43-4db9-a9d0-b0b56cd78e48
  4. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 1
    Logic
    OR
    Version bounds
    from including 3.3; through excluding 3.4.91
    Match ID
    992bfd6a-701c-4412-9220-f6c77b4e64f3
  5. cpe:2.3:o:linux:linux_kernel:2.6.31:rc3:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 6
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    a2507858-675b-4da2-a49e-00db54700cf3
  6. cpe:2.3:o:linux:linux_kernel:2.6.31:rc7:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 10
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    210bf049-8b3c-4acc-bf8e-2c3551477602
  7. cpe:2.3:o:linux:linux_kernel:2.6.31:rc5:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 8
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    b2665356-4ef5-4543-ad15-67fdb851dccd
  8. cpe:2.3:o:linux:linux_kernel:2.6.31:rc8:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 11
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    1837f32c-80d3-4e10-ae5d-e9f5a11a434e
  9. cpe:2.3:o:linux:linux_kernel:2.6.31:rc9:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 12
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    4b4e132b-a69a-4cd1-b4d9-e17c4361a3ac
  10. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 4
    Logic
    OR
    Version bounds
    from including 3.13; through excluding 3.14.4
    Match ID
    9996644c-371e-49b9-a494-733b1ea513ec
  11. cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 0
    Logic
    OR
    Version bounds
    from excluding 2.6.31; through excluding 3.2.59
    Match ID
    ffdb0b31-fff7-471b-9352-29099002bed7
  12. cpe:2.3:o:linux:linux_kernel:2.6.31:rc4:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 7
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    0a25ea55-3f1c-440c-a383-0bb9556c9508
  13. cpe:2.3:o:linux:linux_kernel:2.6.31:rc6:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    0 · node/0 · match 9
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    26e7609b-b058-496d-acdd-7f69fbde89e5
NVD CPE · OPERATING SYSTEMoraclelinuxVulnerable target · 1 assertions
Version 6Canonical identity product-efc63d4e81383a6772c6c41b2fb3231b349512d257b4b47a2475eb5d42511849Linked exact
Scope supported
Inspect raw assertion
  1. cpe:2.3:o:oracle:linux:6:-:*:*:*:*:*:*
    Official link
    Linked exact
    Role
    Vulnerable target
    Configuration
    4 · node/0 · match 0
    Logic
    OR
    Version bounds
    No explicit bounds
    Match ID
    d7b037a8-72a6-4dff-94b2-d688a5f6f876

Affected-product evidence

Accepted scope and product mapping

30 canonical links · 1 source-reported links

Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943f

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b50b84bf-fa3a-48e3-aab7-bc5520c93f53
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-006eb8e0173436b9e5f2c74987109b01caa48599f0370351c5c62638221385d0

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
af5c35c5-816c-440e-bb45-ada86ed29ad4bbb25d69-5c33-4aee-a320-a9d5e438f0dd
Mapping establishedEvidence supported

vendor-9c702362a97e8770255c53f324861f65f3209d35ce95f01842c69a458450f6fa · product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9

Source class
Nvd cpe vulnerable target
Assertions
13
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
053ff4ca-9b44-4aa4-993a-f8c3dd862ce01f9d86f7-0de4-4a03-b681-6e7cacf30b7f20f6f8a3-85dd-43c6-99ab-2d8cd20454db2db3c45a-0b3e-4c72-a762-b1152a8472c23707b943-35c7-4e14-b14a-ab5c592f72094e9668b5-693c-499e-9f33-8d2d422da9ad54cf86ba-f691-4bf9-8ed0-1f3d19d906a17746c08b-b515-46e7-9b8b-dc6684b4a05e778a7397-1591-4915-a855-44fdd05b8e5c9dc806e5-df47-4da2-bcdc-02f902ecc54db739cb45-0a6c-446f-bbbc-b38173482768d03f16d6-035e-4a27-93ac-da9d2c18d5c7f87d8059-ce59-4522-9cbd-2018b734c99f
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-1034b13a364737235c88557ca41a25f206ac20c0fab2a19375ad42f5bbd94b3c

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
11e8bd55-ab63-4146-8bbd-3ba221431b30
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-1220950f14941e44f97ef359dfe4710143870ab715db6bc680fb3bcf3da40d5b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
fbd024f7-e47b-41df-bca1-7b00600b0f8c
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-1328f0fc37701e8fa6b4c8e4957cb3081d1e02cff26e2087bb4ce6b905d5da60

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
14bf947c-ba34-4f55-ac7b-a259f0555b48
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-1bf32c16a3b62f96b746809fb185242f3cb6ddf0e8a05e63872d6eec958472d6

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f3b6dbe7-7725-4506-b6bc-eb0cfaec6096
Mapping establishedEvidence supported

vendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-29144381490373020d031faa229693c1e3e7d7d90a6be50ece9856b5e92fdbfd

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
977a6d5e-f39d-43e2-afef-c982627641d4
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-2ef3e3330ef867854f3e55800c0e0cdd023371aa73dd9e7add7dfa128e66c26a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
be431d7b-c19c-40a4-ac31-eb6f2ec512a6
Mapping establishedEvidence supported

vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
b17922c1-1756-46e5-ada9-3479349745d4d44f99a5-ccab-4c0d-8b11-37388fa696ad
Mapping establishedEvidence supported

vendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-5fa06bd786448a3792b52f67f334b26af471d37e9a7e413134395903848e095c

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
24731c88-5474-4498-bb7f-43c70a822ac6f100cb8d-382b-4abe-8a9b-35239e5693ab
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
449d76f7-05bd-4737-bc75-3cb122a00dd1
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-64a87e2f5b8db7cf37895c491723c860754a6486575c5ac3cbbe3d7cf58a3478

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4313d891-9ff1-4d7b-9e22-1e86e7404c8d
Mapping establishedEvidence supported

vendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-804f9e7741147e62b0e40134bf143d655f1cafba99f0ae98035093f2209d1dc7

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4ec6bb31-64fd-42cb-93ee-565030861643
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dab

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
6cca01af-2672-4ac4-b16c-76f0721b83ba
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378

Source class
Nvd cpe vulnerable target
Assertions
2
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0c2824b9-e5e2-4bf4-934b-e57b76e61746777a0923-0db7-4898-80fd-6ad4abeee983
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-9a98c46bb3d6ba9611bd32eab93edabd599af91bf31121c045dc220d5c65e47b

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
fd159675-8953-486d-bf05-cb5dcf240414
Mapping establishedEvidence supported

vendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2

Source class
Nvd cpe vulnerable target
Assertions
5
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
095a5db8-a5ff-4707-a5fe-0ec1b93f318879475db1-ab1f-45db-9138-be6ad90a5d1f83635896-d1bd-4365-8b21-b7e52ed9bcffa80cf2a0-587f-45f8-a9b5-7d863a2b3a7ae03e6e32-621b-4e7b-b929-64a264c29747
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b8aa0349e7204b53f4ad3e4f173c83d7535e55b4e37cfc14d47a2aed72c1a867

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
45ae5554-03b8-43c5-9763-b66e88b37589
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
c5ff5123-44a1-4edd-9ac3-de8e951602e5
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803da

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
56639b8f-ad68-45f2-a9e2-405056104aba
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
0b487d6e-0914-40c9-adfd-a0c8aa2184f6
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c292d03866ff8f16359315a2e8a89dcc4f7e5d70bc08cbce1625d4ee2032777a

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
8863b940-adb8-4bac-9def-d7f306f154d7
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c606d5370e1ae0f499fdbd5035f77ca02d8a84a54acabd597edb41f7a7690295

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
9c3034ae-7efe-4538-86c8-f8378044c423
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
4ed4c145-88d8-4e6a-9ac2-b6629c745157
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-da9ac0561bce1fb3f2be50345c74276dffd0904067ef9858397b76a9fb869f4c

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
17ec4695-f2f8-4e69-a1c9-8e5bf000fcd5
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
fa89fd21-3a82-42c5-bac2-c326ad835024
Mapping establishedEvidence supported

vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844ee

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
f5bd09ea-c799-4cd8-b065-80a38fe83c4b
Mapping establishedEvidence supported

vendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-efc63d4e81383a6772c6c41b2fb3231b349512d257b4b47a2475eb5d42511849

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
d29844cf-7ad5-4aa5-842f-a61b264be48b
Mapping establishedEvidence supported

vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cb

Source class
Nvd cpe vulnerable target
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
fd55cea6-0589-4ec5-8387-004cc6769350
Source-reported scopeSource-reported scope

Canonical linkage remains open; the cited source assertion is retained below.

Vendor specified only by source · Product specified only by source

Source class
Direct cve affected
Assertions
1
Mapping revision
cpe23-exact-mapping-v1
Observed cutoff
Aug 27, 2026
Retained assertion IDs
7f3722cd-588e-46a8-824a-c6ff31a2c98e

Assessments

CVSS by origin

6.9
NVDCVSS 2.0 · role Primary · priority eligiblevalid_matchAV:L/AC:M/Au:N/C:C/I:C/A:C
5.5
CVE Program sourceCVSS 3.1 · role Secondary · priority eligiblevalid_matchCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
5.5
CISA-ADPCVSS 3.1 · role unknown · display onlyDirect record assessment retained outside normalized eligibilityCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

Direct CVE/CNA normalized decisions

5.5Priority eligible

CISA-ADP

CVSS 3.1 · Secondary · Independent enrichment · rank 2

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Validation
Valid match
Recomputed
5.5
Decision reason
Evidence supported
Policy
casca-direct-cvss-eligibility-v1

Assessments are retained side by side under closed precedence. Cascade never averages CVSS.

Evidence boundaries

  • KEV membership is authoritative for the catalog, not proof of exposure in any environment.
  • EPSS is a dated model probability and not an individual-environment prediction.
  • Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
  • NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
  • Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
  • NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
  • Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
  • OSV aggregation and OSV-converted NVD material are not independent corroboration.
  • Red Hat facts are vendor assertions for the exact supplied products.
  • Nonmembership and not-yet-observed states are not proof of safety.