CVE-2014-3647
5.5 · MEDIUMOverview
CVE-2014-3647 is a medium-severity vulnerability affecting linux linux_kernel. It was published on November 10, 2014 and has a CVSS 3.1 base score of 5.5 (MEDIUM).
This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.
Technical Description
arch/x86/kvm/emulate.c in the KVM subsystem in the Linux kernel through 3.17.2 does not properly perform RIP changes, which allows guest OS users to cause a denial of service (guest OS crash) via a crafted application.
Remediation
Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
Affected Products
| Vendor | Product | Versions | Status |
|---|---|---|---|
| linux | linux_kernel | 0 | Affected |
References
Frequently Asked Questions
What is CVE-2014-3647?
CVE-2014-3647 is a medium-severity vulnerability affecting linux linux_kernel. It was published on November 10, 2014 and has a CVSS 3.1 base score of 5.5 (MEDIUM).
How severe is CVE-2014-3647?
This vulnerability has a CVSS 3.1 base score of 5.5, rated MEDIUM. It requires local or adjacent network access to exploit. No authentication or special privileges are required for exploitation.
How do I fix or remediate CVE-2014-3647?
Check the references section for vendor advisories and patches from linux. Update linux_kernel to the latest patched version. If immediate patching is not possible, review the CVSS vector to understand the attack surface and apply compensating controls such as network segmentation or access restrictions.
How can CyberStrike help with CVE-2014-3647?
CyberStrike's AI-powered security agents can automatically detect CVE-2014-3647 across your infrastructure using autonomous pentesting, DAST scanning, and HackBrowser. The platform continuously monitors for known vulnerabilities and provides actionable remediation guidance prioritized by real-world exploitability.
How CyberStrike Helps
AI agents map your attack surface to find vulnerabilities like this one.
Automated penetration testing that runs continuously, not just quarterly.
AI-driven PR review catches vulnerable dependencies before they ship.
Browser-based exploitation validates findings with real proof-of-concept.
Related MEDIUM CVEs from 2014
View all →Sophos Disk Encryption (SDE) 5.x in Sophos Enterprise Console (SEC) 5.x before 5.2.2 does not enforc
The png_do_expand_palette function in libpng before 1.6.8 allows remote attackers to cause a denial
A flaw was found in Spacewalk, as used in Red Hat Network Satellite. This open redirect vulnerabilit
The Microsoft.XMLDOM ActiveX control in Microsoft Windows 8.1 and earlier allows remote attackers to
The verify_host_key function in sshconnect.c in the client in OpenSSH 6.6 and earlier allows remote
Heap-based buffer overflow in the read_u32 function in Mozilla Firefox before 29.0, Firefox ESR 24.x
Integer overflow in the png_set_unknown_chunks function in libpng/pngset.c in libpng before 1.5.14be
Multiple integer overflows in libpng before 1.5.14rc03 allow remote attackers to cause a denial of s
IBM InfoSphere BigInsights before 2.1.0.3 allows remote authenticated users to bypass intended file
The cdf_read_short_sector function in cdf.c in file before 5.19, as used in the Fileinfo component i
Buffer overflow in the mconvert function in softmagic.c in file before 5.19, as used in the Fileinfo
The cdf_count_chain function in cdf.c in file before 5.19, as used in the Fileinfo component in PHP