CVE-2014-1739

Exp

The media_device_enum_entities function in drivers/media/media-device.c in the Linux kernel before 3.14.6 does not initialize a certain data structure, which allows local users to obtain sensitive information from kernel memory by leveraging /dev/media0 read access for a MEDIA_IOC_ENUM_ENTITIES ioctl call.

Published: 2014-06-23 Last update: 2026-06-16 Assigner: [email protected] Source: [email protected]

Conclusion & alert: CVE-2014-1739 is rated Exploit Available (50/100): CVSS Low severity, with medium exploitation likelihood (EPSS 1.12%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.

Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.

Public exploit references (Exploit-DB) for CVE-2014-1739

EDB-ID Source Kind Published Link
39214 exploit_db edb 2014-05-28 Exploit-DB ↗

Exploit prediction scoring system (EPSS) score for CVE-2014-1739

EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).

# Date Old EPSS score New EPSS score Delta (New - Old)
1 2026-06-15 0.14% 1.12% +0.98%
2 2025-05-21 0.15% 0.14% -0.01%
3 2025-03-30 0.15%

Full EPSS history (8 records total)

Common vulnerability scoring system (CVSS) metrics for CVE-2014-1739

CVSS metrics for this CVE.

Base score Version Severity Vector Exploitability Impact Score source
2.1 2.0 LOW
AV:L/AC:L/Au:N/C:P/I:N/A:N Click to expand
Access vector (AV:L)
Requires local access to the target system.
Access complexity (AC:L)
Exploitation conditions are straightforward and predictable.
Authentication (AU:N)
No authentication is required.
Confidentiality impact (C:P)
Partial confidentiality impact.
Integrity impact (I:N)
No integrity impact.
Availability impact (A:N)
No availability impact.
3.9 2.9 [email protected]

Weakness enumeration for CVE-2014-1739

OS Trackers for CVE-2014-1739

vendor priority summary link
debian unimportant CVE-2014-1739 unimportant priority: Debian including 1 source packages (linux), 5 status rows across 5 suites (bookworm, bullseye, forky, sid, trixie): resolved 5. https://security-tracker.debian.org/tracker/CVE-2014-1739
redhat low https://access.redhat.com/security/cve/CVE-2014-1739
ubuntu medium CVE-2014-1739 medium priority: Ubuntu including 31 source packages (linux, linux-2.6, …), 306 status rows across 11 suites (lucid, precise, saucy, trusty, upstream, utopic, vivid, wily, xenial, yakkety, zesty): DNE 215, released 40, ignored 30, not-affected 21. https://ubuntu.com/security/CVE-2014-1739

Affected software / configurations for CVE-2014-1739

Vendor Product Version Raw CPE
linux linux_kernel < 3.14.6 cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
canonical ubuntu_linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
canonical ubuntu_linux 13.10 cpe:2.3:o:canonical:ubuntu_linux:13.10:*:*:*:*:*:*:*
suse linux_enterprise_high_availability_extension 11 cpe:2.3:o:suse:linux_enterprise_high_availability_extension:11:sp3:*:*:*:*:*:*
suse suse_linux_enterprise_desktop 11 cpe:2.3:o:suse:suse_linux_enterprise_desktop:11:sp3:*:*:*:*:*:*
suse suse_linux_enterprise_server 11 cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp3:*:*:*:-:*:*
suse suse_linux_enterprise_server 11 cpe:2.3:o:suse:suse_linux_enterprise_server:11:sp3:*:*:*:vmware:*:*

References for CVE-2014-1739

URL Tags
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=e6a623460e5fc960ac3ee9f946d3106233fd28d8
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html
http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html
http://secunia.com/advisories/59597
http://speirofr.appspot.com/cve-2014-1739-kernel-infoleak-vulnerability-in-media_enum_entities.html
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.14.6
http://www.openwall.com/lists/oss-security/2014/06/15/1
http://www.securityfocus.com/bid/68048
http://www.securitytracker.com/id/1038201
http://www.ubuntu.com/usn/USN-2259-1
http://www.ubuntu.com/usn/USN-2261-1
http://www.ubuntu.com/usn/USN-2263-1
http://www.ubuntu.com/usn/USN-2264-1
https://bugzilla.redhat.com/show_bug.cgi?id=1109774
https://github.com/torvalds/linux/commit/e6a623460e5fc960ac3ee9f946d3106233fd28d8
https://source.android.com/security/bulletin/2017-04-01
cvelogic Threat Intelligence