CISA KEV · catalog date May 12, 2023 · first observed Jul 19, 2026
Evidence dossier
CVE-2014-0196
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local…
Exploited in the wild (CISA KEV since May 12, 2023). NVD reports CVSS 2.0 6.9. EPSS estimates 22.5% exploit likelihood as of Aug 27, 2026.
As of Aug 27, 2026
Normalized restatement
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
- State
- PUBLISHED
- Published
- May 7, 2014
- Updated
- Oct 22, 2025
- Evidence coverage
- 99%
Evidence chronology
What was known when
- Source dateSource date omittedFirst observed by CASCACISA-ADPOriginal evidence ↗
Record text: CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
- Source dateSource date omittedFirst observed by CASCACVE ProgramOriginal evidence ↗
Record text: CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
- Source dateSource date omittedFirst observed by CASCAredhatOriginal evidence ↗
Record text: The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
Inspect raw assertion
- Field
container- Value
- The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
- Source dateFirst observed by CASCACISA KEVOriginal evidence ↗
Exploitation cataloged: Linux Kernel Race Condition Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Race Condition Vulnerability
- Source dateFirst observed by CASCAFIRST EPSSOriginal evidence ↗
EPSS score: 22.48% probability · 97.53th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.224750000000; percentile 0.975280000000
FIRST EPSS · score date Aug 27, 2026 · 97.5th percentile · first observed Aug 27, 2026
NVD · CVSS 2.0 · first observed Jul 19, 2026 · same-version scores align in this snapshot
Evidence detail
Source limits and decisions
Why each evidence state has this value
casca-unknown-reasons-v1Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- evidence-policy-v1.1.0
- Cutoff
- Aug 27, 2026
- Resolution
- None
Eligible evidence is present for this bounded claim.
- Revision
- casca-direct-cvss-eligibility-v1
- Cutoff
- Aug 27, 2026
- Resolution
- None
The cited source assertion is retained while canonical product linkage remains open.
- Revision
- casca-factor-d-obligations-v1
- Cutoff
- Aug 27, 2026
- Resolution
- Resolve identity
Source comparison
Who said what
CISA ADP Vulnrichment
Inspect raw assertion
- Field
container- Value
- CISA ADP Vulnrichment
CVE Program Container
Inspect raw assertion
- Field
container- Value
- CVE Program Container
The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
Inspect raw assertion
- Field
container- Value
- The n_tty_write function in drivers/tty/n_tty.c in the Linux kernel through 3.14.3 does not properly manage tty driver access in the "LECHO & !OPOST" case, which allows local users to cause a denial of service (memory corruption and system crash) or gain privileges by triggering a race condition involving read and write operations with long strings.
Linux Kernel Race Condition Vulnerability
Inspect raw assertion
- Field
observed_exploitation- Value
- Linux Kernel Race Condition Vulnerability
22.48% probability · 97.53th percentile
Inspect raw assertion
- Field
model_probability- Value
- Probability 0.224750000000; percentile 0.975280000000
Applicability
Cited product scope
Grouped from 7 configuration nodes in this exact snapshot. Visual grouping is navigational; asset exposure and root cause require cited evidence.
Identity source boundaries
- Cpe dictionary1,775,266 records · observed through 2026-07-21T06:45:29.809Z
27d65b0f-b718-4b4f-bb79-c47c68d09dfa - Cpe match643,502 records · observed through 2026-07-21T08:13:17.697Z
955dae73-7302-438b-aee1-058d7cc5d48e
31 scope groups
Canonical linkage remains open; the cited source assertion is retained below.
Inspect raw assertion
[{"status": "affected", "version": "n/a"}]product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2Linked exactInspect raw assertions
cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
8d305f7a-d159-4716-ab26-5e38bb5cd991
cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 4
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
815d70a8-47d3-459c-a32c-9feaca0659d1
cpe:2.3:o:canonical:ubuntu_linux:12.10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 2
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e2076871-2e80-4605-a470-a41c1a8ec7ee
cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
01eda41c-6b2e-49af-b503-eb3882265c11
cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 5 · node/0 · match 3
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
7f61f047-129c-41a6-8a27-ffcbb8563e91
product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447eLinked exactInspect raw assertions
cpe:2.3:o:debian:debian_linux:7.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 1
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
16f59a04-14cf-49e2-9973-645477ea09da
cpe:2.3:o:debian:debian_linux:6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 1 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
036e8a89-7a16-411f-9d31-676313bb7244
product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cbLinked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_access_policy_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 0
- Logic
- OR
- Version bounds
- from including 11.1.0; through including 11.5.1
- Match ID
8f315708-017c-4362-9c09-6774f89d9370
product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36Linked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_advanced_firewall_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 11.3.0; through including 11.5.1
- Match ID
48bbef73-e87d-467f-85eb-47be212df0e8
product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943fLinked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_analytics:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 11.1.0; through including 11.5.1
- Match ID
a430ffb4-418c-43da-8e17-020618a77a56
product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078Linked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_application_acceleration_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 11.4.0; through including 11.5.1
- Match ID
c483253f-841e-4d4e-9b4a-932e9d07268b
product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803daLinked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_application_security_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 4
- Logic
- OR
- Version bounds
- from including 11.1.0; through including 11.5.1
- Match ID
7a0cc74c-6914-4a6f-a1ce-65a695ae31f6
product-2ef3e3330ef867854f3e55800c0e0cdd023371aa73dd9e7add7dfa128e66c26aLinked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_edge_gateway:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 5
- Logic
- OR
- Version bounds
- from including 11.1.0; through including 11.3.0
- Match ID
9ff30167-0241-4136-82f8-2d2fb545c19a
product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0Linked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_global_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 6
- Logic
- OR
- Version bounds
- from including 11.1.0; through including 11.5.1
- Match ID
54a45725-fecd-4ca9-bfa4-e13fcdfddf13
product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dabLinked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_link_controller:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 7
- Logic
- OR
- Version bounds
- from including 11.1.0; through including 11.5.1
- Match ID
8c596b3f-9d93-49d2-99d7-d590cc9aeaa5
product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81Linked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_local_traffic_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 8
- Logic
- OR
- Version bounds
- from including 11.1.0; through including 11.5.1
- Match ID
d8696a6b-1b56-43b5-a506-21e17735b9ca
product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3Linked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_policy_enforcement_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 9
- Logic
- OR
- Version bounds
- from including 11.3.0; through including 11.5.1
- Match ID
e9a06d61-e6cb-4a8a-b06d-9fea1812c167
product-c292d03866ff8f16359315a2e8a89dcc4f7e5d70bc08cbce1625d4ee2032777aLinked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_protocol_security_module:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 10
- Logic
- OR
- Version bounds
- from including 11.1.0; through including 11.4.1
- Match ID
8c666a18-9ded-4b49-92de-474403fc17bf
product-da9ac0561bce1fb3f2be50345c74276dffd0904067ef9858397b76a9fb869f4cLinked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_wan_optimization_manager:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 11
- Logic
- OR
- Version bounds
- from including 11.1.0; through including 11.3.0
- Match ID
a6b52d60-38db-4be9-91f4-b6553f5e5a93
product-9a98c46bb3d6ba9611bd32eab93edabd599af91bf31121c045dc220d5c65e47bLinked exactInspect raw assertion
cpe:2.3:a:f5:big-ip_webaccelerator:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 12
- Logic
- OR
- Version bounds
- from including 11.1.0; through including 11.3.0
- Match ID
e1e3204f-9464-4ac3-819b-d1a6b399fae3
product-1328f0fc37701e8fa6b4c8e4957cb3081d1e02cff26e2087bb4ce6b905d5da60Linked exactInspect raw assertion
cpe:2.3:a:f5:big-iq_application_delivery_controller:4.5.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 13
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
222b4de7-1d3d-40df-a9eb-efabda8faea6
product-c606d5370e1ae0f499fdbd5035f77ca02d8a84a54acabd597edb41f7a7690295Linked exactInspect raw assertion
cpe:2.3:a:f5:big-iq_centralized_management:4.6.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 14
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
24aef0b2-7c8c-432c-a840-c2441a70343f
product-b8aa0349e7204b53f4ad3e4f173c83d7535e55b4e37cfc14d47a2aed72c1a867Linked exactInspect raw assertion
cpe:2.3:a:f5:big-iq_cloud:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 15
- Logic
- OR
- Version bounds
- from including 4.0.0; through including 4.5.0
- Match ID
8c8bf865-ba45-4711-829f-ec8e5ea22d2f
product-1034b13a364737235c88557ca41a25f206ac20c0fab2a19375ad42f5bbd94b3cLinked exactInspect raw assertion
cpe:2.3:a:f5:big-iq_cloud_and_orchestration:1.0.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 16
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
e21d6206-4716-47fe-a733-f18343656e94
product-64a87e2f5b8db7cf37895c491723c860754a6486575c5ac3cbbe3d7cf58a3478Linked exactInspect raw assertion
cpe:2.3:a:f5:big-iq_device:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 17
- Logic
- OR
- Version bounds
- from including 4.2.0; through including 4.5.0
- Match ID
3bc0eafd-da5e-4a1b-81cb-0d5a964f9eb6
product-1bf32c16a3b62f96b746809fb185242f3cb6ddf0e8a05e63872d6eec958472d6Linked exactInspect raw assertion
cpe:2.3:a:f5:big-iq_security:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 18
- Logic
- OR
- Version bounds
- from including 4.0.0; through including 4.5.0
- Match ID
6b3e56eb-202a-4f58-8e94-b2dda1693498
product-006eb8e0173436b9e5f2c74987109b01caa48599f0370351c5c62638221385d0Linked exactInspect raw assertions
cpe:2.3:a:f5:enterprise_manager:3.1.0:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 19
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4c580f19-af18-49ee-89ff-8c4f5c88314d
cpe:2.3:a:f5:enterprise_manager:3.1.1:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 6 · node/0 · match 20
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d5f5fee7-059a-4a9b-bccd-18f0aa435040
product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9Linked exactInspect raw assertions
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 2
- Logic
- OR
- Version bounds
- from including 3.5; through excluding 3.10.40
- Match ID
287dc65b-a513-4fb9-a1cf-69f428030df8
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 3
- Logic
- OR
- Version bounds
- from including 3.11; through excluding 3.12.20
- Match ID
d82f8c94-5fa7-4a7a-8855-ecf21b3bbd42
cpe:2.3:o:linux:linux_kernel:2.6.31:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 5
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
2887290a-1b43-4db9-a9d0-b0b56cd78e48
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 1
- Logic
- OR
- Version bounds
- from including 3.3; through excluding 3.4.91
- Match ID
992bfd6a-701c-4412-9220-f6c77b4e64f3
cpe:2.3:o:linux:linux_kernel:2.6.31:rc3:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 6
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
a2507858-675b-4da2-a49e-00db54700cf3
cpe:2.3:o:linux:linux_kernel:2.6.31:rc7:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 10
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
210bf049-8b3c-4acc-bf8e-2c3551477602
cpe:2.3:o:linux:linux_kernel:2.6.31:rc5:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 8
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
b2665356-4ef5-4543-ad15-67fdb851dccd
cpe:2.3:o:linux:linux_kernel:2.6.31:rc8:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 11
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
1837f32c-80d3-4e10-ae5d-e9f5a11a434e
cpe:2.3:o:linux:linux_kernel:2.6.31:rc9:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 12
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
4b4e132b-a69a-4cd1-b4d9-e17c4361a3ac
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 4
- Logic
- OR
- Version bounds
- from including 3.13; through excluding 3.14.4
- Match ID
9996644c-371e-49b9-a494-733b1ea513ec
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 0
- Logic
- OR
- Version bounds
- from excluding 2.6.31; through excluding 3.2.59
- Match ID
ffdb0b31-fff7-471b-9352-29099002bed7
cpe:2.3:o:linux:linux_kernel:2.6.31:rc4:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 7
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
0a25ea55-3f1c-440c-a383-0bb9556c9508
cpe:2.3:o:linux:linux_kernel:2.6.31:rc6:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 0 · node/0 · match 9
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
26e7609b-b058-496d-acdd-7f69fbde89e5
product-efc63d4e81383a6772c6c41b2fb3231b349512d257b4b47a2475eb5d42511849Linked exactInspect raw assertion
cpe:2.3:o:oracle:linux:6:-:*:*:*:*:*:*- Official link
- Linked exact
- Role
- Vulnerable target
- Configuration
- 4 · node/0 · match 0
- Logic
- OR
- Version bounds
- No explicit bounds
- Match ID
d7b037a8-72a6-4dff-94b2-d688a5f6f876
Affected-product evidence
Accepted scope and product mapping
30 canonical links · 1 source-reported links
vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-000cb533806b78ef860fa6bff163646e9d5756ef6c2d4d7d222692c4cd4c943f
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b50b84bf-fa3a-48e3-aab7-bc5520c93f53vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-006eb8e0173436b9e5f2c74987109b01caa48599f0370351c5c62638221385d0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
af5c35c5-816c-440e-bb45-ada86ed29ad4bbb25d69-5c33-4aee-a320-a9d5e438f0ddvendor-9c702362a97e8770255c53f324861f65f3209d35ce95f01842c69a458450f6fa · product-0eda7a801761be4590f267cf319481c8c0aaa30546d99cc064edf77989ce05c9
- Source class
- Nvd cpe vulnerable target
- Assertions
- 13
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
053ff4ca-9b44-4aa4-993a-f8c3dd862ce01f9d86f7-0de4-4a03-b681-6e7cacf30b7f20f6f8a3-85dd-43c6-99ab-2d8cd20454db2db3c45a-0b3e-4c72-a762-b1152a8472c23707b943-35c7-4e14-b14a-ab5c592f72094e9668b5-693c-499e-9f33-8d2d422da9ad54cf86ba-f691-4bf9-8ed0-1f3d19d906a17746c08b-b515-46e7-9b8b-dc6684b4a05e778a7397-1591-4915-a855-44fdd05b8e5c9dc806e5-df47-4da2-bcdc-02f902ecc54db739cb45-0a6c-446f-bbbc-b38173482768d03f16d6-035e-4a27-93ac-da9d2c18d5c7f87d8059-ce59-4522-9cbd-2018b734c99fvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-1034b13a364737235c88557ca41a25f206ac20c0fab2a19375ad42f5bbd94b3c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
11e8bd55-ab63-4146-8bbd-3ba221431b30vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-1220950f14941e44f97ef359dfe4710143870ab715db6bc680fb3bcf3da40d5b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fbd024f7-e47b-41df-bca1-7b00600b0f8cvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-1328f0fc37701e8fa6b4c8e4957cb3081d1e02cff26e2087bb4ce6b905d5da60
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
14bf947c-ba34-4f55-ac7b-a259f0555b48vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-1bf32c16a3b62f96b746809fb185242f3cb6ddf0e8a05e63872d6eec958472d6
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f3b6dbe7-7725-4506-b6bc-eb0cfaec6096vendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-29144381490373020d031faa229693c1e3e7d7d90a6be50ece9856b5e92fdbfd
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
977a6d5e-f39d-43e2-afef-c982627641d4vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-2ef3e3330ef867854f3e55800c0e0cdd023371aa73dd9e7add7dfa128e66c26a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
be431d7b-c19c-40a4-ac31-eb6f2ec512a6vendor-66ae8c5e06427f7450637d18322b0dc411c0b469d940341cf076a620d444fe3c · product-3ccb4bc87dfae98fa2f2a06435fe5b3d9be78572fb958a89f2d7a96b4066447e
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
b17922c1-1756-46e5-ada9-3479349745d4d44f99a5-ccab-4c0d-8b11-37388fa696advendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-5fa06bd786448a3792b52f67f334b26af471d37e9a7e413134395903848e095c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
24731c88-5474-4498-bb7f-43c70a822ac6f100cb8d-382b-4abe-8a9b-35239e5693abvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-618e73be1c78cebd98c0451389a4bfe0fed7033b9a99c5dfef4ab081a1711fd0
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
449d76f7-05bd-4737-bc75-3cb122a00dd1vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-64a87e2f5b8db7cf37895c491723c860754a6486575c5ac3cbbe3d7cf58a3478
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4313d891-9ff1-4d7b-9e22-1e86e7404c8dvendor-6bbcd126779403146e957d68529786b086421e0676d9e90a4d53d03594694fb2 · product-804f9e7741147e62b0e40134bf143d655f1cafba99f0ae98035093f2209d1dc7
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4ec6bb31-64fd-42cb-93ee-565030861643vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-8754268b8c2cde0fe6aca92689e07534654bf0c32f504fdc7eabdc3dd51c0dab
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
6cca01af-2672-4ac4-b16c-76f0721b83bavendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-8abf8d7f0342f690712d750b6cf7fbf4068eb0134c40a51c5b57b074f81c6378
- Source class
- Nvd cpe vulnerable target
- Assertions
- 2
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0c2824b9-e5e2-4bf4-934b-e57b76e61746777a0923-0db7-4898-80fd-6ad4abeee983vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-9a98c46bb3d6ba9611bd32eab93edabd599af91bf31121c045dc220d5c65e47b
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fd159675-8953-486d-bf05-cb5dcf240414vendor-c57a6167e95991f72f9616ac32b40463ac13c5f4929fcce3efc058b09a445b54 · product-a18840e4673d48e569064752e9575849e99b3f173c63d7c965c4c193bcaebef2
- Source class
- Nvd cpe vulnerable target
- Assertions
- 5
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
095a5db8-a5ff-4707-a5fe-0ec1b93f318879475db1-ab1f-45db-9138-be6ad90a5d1f83635896-d1bd-4365-8b21-b7e52ed9bcffa80cf2a0-587f-45f8-a9b5-7d863a2b3a7ae03e6e32-621b-4e7b-b929-64a264c29747vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b8aa0349e7204b53f4ad3e4f173c83d7535e55b4e37cfc14d47a2aed72c1a867
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
45ae5554-03b8-43c5-9763-b66e88b37589vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-b94ca11deae6f3dbdfe71c801d37911c9fd185c5bd3c37c804c67d15918d47d3
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
c5ff5123-44a1-4edd-9ac3-de8e951602e5vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-ba5b29ee89c2340743c5ed2999e757bf44af0086b8b527afdbbe3f8a626803da
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
56639b8f-ad68-45f2-a9e2-405056104abavendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-bcf09b1e7f256f8ae475f16dc9eb0c89893ad01b1d9c94b66d17ac875578a078
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
0b487d6e-0914-40c9-adfd-a0c8aa2184f6vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c292d03866ff8f16359315a2e8a89dcc4f7e5d70bc08cbce1625d4ee2032777a
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
8863b940-adb8-4bac-9def-d7f306f154d7vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c606d5370e1ae0f499fdbd5035f77ca02d8a84a54acabd597edb41f7a7690295
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
9c3034ae-7efe-4538-86c8-f8378044c423vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-c611bfdeac48cac2141d0aebba0e7ba6ff1c599d72cfe95a76f1db1b7fe68b36
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
4ed4c145-88d8-4e6a-9ac2-b6629c745157vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-da9ac0561bce1fb3f2be50345c74276dffd0904067ef9858397b76a9fb869f4c
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
17ec4695-f2f8-4e69-a1c9-8e5bf000fcd5vendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-dfc8c075c3b90f711dd6c07c1d70e2c3507742bbcffef3651f2737a4133eeb81
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fa89fd21-3a82-42c5-bac2-c326ad835024vendor-c759fafc60d6abc1277ecbf1ee6294d1f25ae0a4c7d5d0d9355c414b2db182cc · product-ec20120153af988d42a6a2dfd3cdd9595762b35581f66014faaa4f85d8f844ee
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
f5bd09ea-c799-4cd8-b065-80a38fe83c4bvendor-b1377626da187dbea1eeb98f365c57a3dcbeccfdc2a7d3471e94ece7b6f88e55 · product-efc63d4e81383a6772c6c41b2fb3231b349512d257b4b47a2475eb5d42511849
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
d29844cf-7ad5-4aa5-842f-a61b264be48bvendor-9aa6446e33f571cc7bda8ab13a2370bdcc16dba7a4e698b5ebc0a2b8d98b481c · product-fe8f45eed4bb3ac6e69f6f6fbf87e9e25862951e870386e176dca756ebfdb2cb
- Source class
- Nvd cpe vulnerable target
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
fd55cea6-0589-4ec5-8387-004cc6769350Canonical linkage remains open; the cited source assertion is retained below.
Vendor specified only by source · Product specified only by source
- Source class
- Direct cve affected
- Assertions
- 1
- Mapping revision
- cpe23-exact-mapping-v1
- Observed cutoff
- Aug 27, 2026
Retained assertion IDs
7f3722cd-588e-46a8-824a-c6ff31a2c98eAssessments
CVSS by origin
AV:L/AC:M/Au:N/C:C/I:C/A:CCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HDirect CVE/CNA normalized decisions
CISA-ADP
CVSS 3.1 · Secondary · Independent enrichment · rank 2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H- Validation
- Valid match
- Recomputed
- 5.5
- Decision reason
- Evidence supported
- Policy
- casca-direct-cvss-eligibility-v1
Assessments are retained side by side under closed precedence. Cascade never averages CVSS.
Evidence boundaries
- KEV membership is authoritative for the catalog, not proof of exposure in any environment.
- EPSS is a dated model probability and not an individual-environment prediction.
- Affected or fixed status applies only to the exact cited product and version scope; remaining scope stays source-scoped.
- NVD-carried upstream facts remain derivative; independent corroboration requires a separately authored source.
- Only NVD metrics validated under the generation-bound calculator are Public Priority eligible; direct CVE record metrics remain display-only.
- NVD CVSS source eligibility is closed: NVD-authored, exact record-source, or registered same-CVE container origin; unmapped sources remain display-only.
- Core replay supports the active and immediately prior generation; retrospective valid-at replay is deferred.
- OSV aggregation and OSV-converted NVD material are not independent corroboration.
- Red Hat facts are vendor assertions for the exact supplied products.
- Nonmembership and not-yet-observed states are not proof of safety.