LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2018-14634: Linux Kernel Integer Overflow Vulnerability

RBRecent Breaches Vulnerability Intelligence·Jan 26, 2026
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Feb 16, 2026
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2018-14634 to its Known Exploited Vulnerabilities catalog on Jan 26, 2026, with a federal patch deadline of Feb 16, 2026 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to…

Linux kernel contains an integer overflow that can allow a local, unprivileged user who can execute an SUID or otherwise privileged binary to gain elevated privileges on the system. The issue is tracked as CVE-2018-14634 and affects the create_elf_tables() function.

How it works

The weakness is classified as CWE-190, integer overflow or wraparound. An attacker supplies input that causes an arithmetic operation inside create_elf_tables() to exceed the maximum value for the data type, producing an incorrect result that the kernel later uses when setting up the process environment.

Am I affected? How to find it in your systems

The vulnerability exists in the Linux kernel and therefore affects any distribution or appliance that ships a vulnerable kernel version. Inventory begins with identifying all systems running Linux, including servers, workstations, containers, and embedded devices.

How to remediate

Apply the vendor-supplied kernel update that corrects the integer handling in create_elf_tables(). This is the primary and most effective action.

If you can't patch immediately

Apply mitigations described in the vendor advisory. Where cloud services are involved, follow applicable BOD 22-01 guidance. If mitigations cannot be implemented, discontinue use of the affected kernel until an update can be applied.

If your data may have been exposed

Local privilege-escalation vulnerabilities that are actively exploited can lead to further compromise and data exposure. You can run a free exposure scan of your email addresses to check for presence in known breach data.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedLinux · Kernel
WeaknessCWE-190
Added to CISA KEVJan 26, 2026
Federal patch deadlineFeb 16, 2026
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities