PoC Index

CVE-2014-9322

HIGH 7.8EPSS 1.4%

arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.

CVSS v3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
1.45% chance of exploitation in the next 30 days, 71th percentile
Published
2014-12-17
Updated
2024-08-06

Proof-of-concept exploits (2)

ExploitDB entries (2)

References

Related