← back
CVE-2014-3631

CVE-2014-3631

23Vexday Risk Score

No sign of exploitation. It has a public proof of concept.

ssvc Attendepss 1.0%
from disclosure to weapon157 days
Published on NVDSep 28
1st PoC+157d
exploitation probability
1.0%top 42% of all CVEs
observed exploitation
nono source reports it
2 public exploit(s)
The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via multiple "keyctl newring" operations followed by a "keyctl timeout" operation.
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.