CVE-2014-9114

high
Published 2017-03-31 · Modified 2026-05-13
CVSS v3
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.2
VIR risk
7.8

Description

Blkid in util-linux before 2.26rc-1 allows local users to execute arbitrary code.

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-9114

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/karelzak/util-linux/commit/89e90ae7b2826110ea28c1c0eb8e7c56c3907bdc

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bugzilla.redhat.com/show_bug.cgi?id=1168485

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.openwall.com/lists/oss-security/2014/11/26/21

OS impact

OSVersionStatusFixed in
suse suse13.1affected
suse suse13.2affected
fedora fedora20affected
fedora fedora21affected
debian debianbookwormfixed2.25.2-4
debian debianbullseyefixed2.25.2-4
debian debianforkyfixed2.25.2-4
debian debiansidfixed2.25.2-4
debian debiantrixiefixed2.25.2-4

Application impact

VendorProductVersionsFixed
kernelutil-linux{"endIncluding":"2.24.2-1"}

References

CWEs

CWE-77

Verify integrity in audit chain (admin only). AS-IS.