CVE-2014-1739

Linux kernel <3.14.6 - Info Disclosure

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2014-1739. PoCs published by Salva Peiro.

AI-analyzed exploit summary This exploit demonstrates an information disclosure vulnerability in the Linux kernel (CVE-2014-1739) by leaking kernel stack memory via the media_device_enum_entities() function. It uses an ioctl call to trigger the leak and prints 200 bytes of kernel stack data.

Description

The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0 read access for a MEDIA_IOC_ENUM_ENTITIES ioctl call.

Exploits (1)

exploitdb WORKING POC VERIFIED
by Salva Peiro · clocallinux
https://www.exploit-db.com/exploits/39214

This exploit demonstrates an information disclosure vulnerability in the Linux kernel (CVE-2014-1739) by leaking kernel stack memory via the media_device_enum_entities() function. It uses an ioctl call to trigger the leak and prints 200 bytes of kernel stack data.

Classification
Working Poc 100%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: Linux kernel 2.6.38 through 3.15-rc2
No auth needed
Prerequisites: Access to /dev/media0 or similar media device file
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (16)

Core 16
Core References
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2263-1
Issue Tracking x_refsource_confirm
https://bugzilla.redhat.com/show_bug.cgi?id=1109774
Mailing List mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/06/15/1
Vendor Advisory x_refsource_confirm
https://source.android.com/security/bulletin/2017-04-01
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2261-1
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2264-1
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/68048
Vendor Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2259-1
Third Party Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/59597
Third Party Advisory, VDB Entry vdb-entry x_refsource_sectrack
http://www.securitytracker.com/id/1038201

Scores

EPSS 0.0010
EPSS Percentile 27.8%

Details

CWE
CWE-200
Status published
Products (6)
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 13.10
linux/linux_kernel < 3.14.6
suse/linux_enterprise_high_availability_extension 11 sp3
suse/suse_linux_enterprise_desktop 11 sp3
suse/suse_linux_enterprise_server 11 sp3 (2 CPE variants)
Published Jun 23, 2014
Tracked Since Feb 18, 2026