A vulnerability in the Linux kernel's compat_sys_recvmmsg function (net/compat.c) prior to version 3.13.2, when CONFIG_X86_X32 is enabled, allows local users to escalate privileges. The flaw is triggered by a crafted recvmmsg system call with a specially crafted timeout pointer parameter, leading to unintended kernel behavior and privilege escalation.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (3 hidden).
This repository contains a single Metasploit module (Ruby file) that exploits CVE-2014-0038, a privilege escalation vulnerability in the Linux kernel's recvmmsg system call. The exploit targets specific Ubuntu kernel versions (3.8.0-19-generic, 3.11.0-12-generic, 3.11.0-15-generic) and allows a local attacker with shell access to gain root privileges. The module uploads an exploit binary (either compiled on the target or pre-compiled), as well as a payload executable (such as a meterpreter or shell), to a writable directory (default: /tmp). It then executes the exploit, which triggers the vulnerability and runs the payload as root. The module includes checks to ensure the target is vulnerable and cleans up after execution. The exploit is operational and provides root access if successful. No network endpoints are involved; the attack vector is purely local privilege escalation.
This repository contains a local privilege escalation exploit for CVE-2014-0038, targeting a vulnerability in the x86_x32 recvmmsg syscall in the Linux kernel. The exploit consists of a C source file (timeoutpwn.c), a build script (build.sh), a README with detailed instructions, and an 'addresses' file listing kernel symbol addresses for various distributions. The exploit works by overwriting the release function pointer in the ptmx_fops structure in kernel memory, redirecting it to a user-mapped payload that escalates privileges to root. The build script extracts necessary kernel addresses from /proc/kallsyms or System.map. The exploit is operational and, if successful, spawns a root shell. It is tested on several Linux distributions and kernel versions, as listed in the 'addresses' file. The attack vector is local, requiring the attacker to execute code on the target system. Key fingerprintable endpoints include /proc/kallsyms, /dev/ptmx, and /bin/bash.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.