{"api_version":"1","generated_at":"2026-07-23T05:43:15+00:00","cve":"CVE-2014-4014","urls":{"html":"https://cve.report/CVE-2014-4014","api":"https://cve.report/api/cve/CVE-2014-4014.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-4014","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-4014"},"summary":{"title":"CVE-2014-4014","description":"The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-06-23 11:21:17","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"6.2","severity":"","vector":"AV:L/AC:H/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:H/Au:N/C:C/I:C/A:C","baseScore":6.2,"accessVector":"LOCAL","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1107966","name":"https://bugzilla.redhat.com/show_bug.cgi?id=1107966","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Issue Tracking","Third Party Advisory"],"title":"Bug 1107966 – CVE-2014-4014 Kernel: possible privilege escalation in user namespace","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=23adbe12ef7d3d4195e80800ab36b37bee28cd03","name":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=23adbe12ef7d3d4195e80800ab36b37bee28cd03","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"http://www.securitytracker.com/id/1030394","name":"http://www.securitytracker.com/id/1030394","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Linux Kernel inode_capable() Incorrect Capability Check Lets Local Users Gain Elevated Privileges - SecurityTracker","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.securityfocus.com/bid/67988","name":"http://www.securityfocus.com/bid/67988","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Linux Kernel CVE-2014-4014 Local Privilege Escalation Vulnerability","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"http://www.exploit-db.com/exploits/33824","name":"http://www.exploit-db.com/exploits/33824","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory","VDB Entry"],"title":"Linux Kernel <= 3.13 - Local Privilege Escalation PoC (gid)","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://source.android.com/security/bulletin/2016-12-01.html","name":"https://source.android.com/security/bulletin/2016-12-01.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"Android Security Bulletin—December 2016 | Android Open Source Project","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://github.com/torvalds/linux/commit/23adbe12ef7d3d4195e80800ab36b37bee28cd03","name":"https://github.com/torvalds/linux/commit/23adbe12ef7d3d4195e80800ab36b37bee28cd03","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"fs,userns: Change inode_capable to capable_wrt_inode_uidgid · torvalds/linux@23adbe1 · GitHub","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.openwall.com/lists/oss-security/2014/06/10/4","name":"http://www.openwall.com/lists/oss-security/2014/06/10/4","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Mailing List","Third Party Advisory"],"title":"oss-security - CVE-2014-4014: Linux kernel user namespace bug","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://secunia.com/advisories/59220","name":"http://secunia.com/advisories/59220","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"],"title":"About Secunia Research | Flexera","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.8","name":"http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.8","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"],"title":"","mime":"text/plain","httpstatus":"200","archivestatus":"200"},{"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=23adbe12ef7d3d4195e80800ab36b37bee28cd03","name":"CONFIRM:http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=23adbe12ef7d3d4195e80800ab36b37bee28cd03","refsource":"MITRE","tags":[],"title":"kernel/git/torvalds/linux.git - Linux kernel source tree","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-4014","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-4014","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"4014","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"linux","cpe5":"linux_kernel","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T11:04:28.054Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"67988","tags":["vdb-entry","x_refsource_BID","x_transferred"],"url":"http://www.securityfocus.com/bid/67988"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://source.android.com/security/bulletin/2016-12-01.html"},{"name":"1030394","tags":["vdb-entry","x_refsource_SECTRACK","x_transferred"],"url":"http://www.securitytracker.com/id/1030394"},{"name":"33824","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/33824"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.8"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://github.com/torvalds/linux/commit/23adbe12ef7d3d4195e80800ab36b37bee28cd03"},{"name":"59220","tags":["third-party-advisory","x_refsource_SECUNIA","x_transferred"],"url":"http://secunia.com/advisories/59220"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1107966"},{"name":"[oss-security] 20140610 CVE-2014-4014: Linux kernel user namespace bug","tags":["mailing-list","x_refsource_MLIST","x_transferred"],"url":"http://www.openwall.com/lists/oss-security/2014/06/10/4"},{"tags":["x_refsource_CONFIRM","x_transferred"],"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=23adbe12ef7d3d4195e80800ab36b37bee28cd03"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-06-10T00:00:00.000Z","descriptions":[{"lang":"en","value":"The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2017-01-18T22:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"67988","tags":["vdb-entry","x_refsource_BID"],"url":"http://www.securityfocus.com/bid/67988"},{"tags":["x_refsource_CONFIRM"],"url":"https://source.android.com/security/bulletin/2016-12-01.html"},{"name":"1030394","tags":["vdb-entry","x_refsource_SECTRACK"],"url":"http://www.securitytracker.com/id/1030394"},{"name":"33824","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/33824"},{"tags":["x_refsource_CONFIRM"],"url":"http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.8"},{"tags":["x_refsource_CONFIRM"],"url":"https://github.com/torvalds/linux/commit/23adbe12ef7d3d4195e80800ab36b37bee28cd03"},{"name":"59220","tags":["third-party-advisory","x_refsource_SECUNIA"],"url":"http://secunia.com/advisories/59220"},{"tags":["x_refsource_CONFIRM"],"url":"https://bugzilla.redhat.com/show_bug.cgi?id=1107966"},{"name":"[oss-security] 20140610 CVE-2014-4014: Linux kernel user namespace bug","tags":["mailing-list","x_refsource_MLIST"],"url":"http://www.openwall.com/lists/oss-security/2014/06/10/4"},{"tags":["x_refsource_CONFIRM"],"url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=23adbe12ef7d3d4195e80800ab36b37bee28cd03"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-4014","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"67988","refsource":"BID","url":"http://www.securityfocus.com/bid/67988"},{"name":"https://source.android.com/security/bulletin/2016-12-01.html","refsource":"CONFIRM","url":"https://source.android.com/security/bulletin/2016-12-01.html"},{"name":"1030394","refsource":"SECTRACK","url":"http://www.securitytracker.com/id/1030394"},{"name":"33824","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/33824"},{"name":"http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.8","refsource":"CONFIRM","url":"http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.8"},{"name":"https://github.com/torvalds/linux/commit/23adbe12ef7d3d4195e80800ab36b37bee28cd03","refsource":"CONFIRM","url":"https://github.com/torvalds/linux/commit/23adbe12ef7d3d4195e80800ab36b37bee28cd03"},{"name":"59220","refsource":"SECUNIA","url":"http://secunia.com/advisories/59220"},{"name":"https://bugzilla.redhat.com/show_bug.cgi?id=1107966","refsource":"CONFIRM","url":"https://bugzilla.redhat.com/show_bug.cgi?id=1107966"},{"name":"[oss-security] 20140610 CVE-2014-4014: Linux kernel user namespace bug","refsource":"MLIST","url":"http://www.openwall.com/lists/oss-security/2014/06/10/4"},{"name":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=23adbe12ef7d3d4195e80800ab36b37bee28cd03","refsource":"CONFIRM","url":"http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git;a=commit;h=23adbe12ef7d3d4195e80800ab36b37bee28cd03"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2014-4014","datePublished":"2014-06-23T10:00:00.000Z","dateReserved":"2014-06-09T00:00:00.000Z","dateUpdated":"2024-08-06T11:04:28.054Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-06-23 11:21:17","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:H/Au:N/C:C/I:C/A:C","baseScore":6.2,"accessVector":"LOCAL","accessComplexity":"HIGH","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"MEDIUM","exploitabilityScore":1.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*","versionEndExcluding":"3.14.8","matchCriteriaId":"07C0B41C-8466-4CBF-B996-6CCD9B07FEFD"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"4014","Ordinal":"1","Title":"CVE-2014-4014","CVE":"CVE-2014-4014","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"4014","Ordinal":"1","NoteData":"The capabilities implementation in the Linux kernel before 3.14.8 does not properly consider that namespaces are inapplicable to inodes, which allows local users to bypass intended chmod restrictions by first creating a user namespace, as demonstrated by setting the setgid bit on a file with group ownership of root.","Type":"Description","Title":"CVE-2014-4014"},{"CveYear":"2014","CveId":"4014","Ordinal":"2","NoteData":"2014-06-23","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"4014","Ordinal":"3","NoteData":"2017-01-18","Type":"Other","Title":"Modified"}]}}}