CVE-2014-9322

high
Published 2014-12-17 · Modified 2026-05-06
CVSS v3
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS v2
7.2
VIR risk
7.8

Description

arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.

Predictions

Exploit likelihood
75%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-9322

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.17.5

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://github.com/torvalds/linux/commit/6f442be2fb22be02cafa606f1769fa1e6f894441

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — https://bugzilla.redhat.com/show_bug.cgi?id=1172806

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://www.openwall.com/lists/oss-security/2014/12/15/6

vendor Authored 2026-05-27

Vendor advisory: cve@mitre.org — http://source.android.com/security/bulletin/2016-04-02.html

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.16.7-ckt2-1
debian debianbullseyefixed3.16.7-ckt2-1
debian debianforkyfixed3.16.7-ckt2-1
debian debiansidfixed3.16.7-ckt2-1
debian debiantrixiefixed3.16.7-ckt2-1
suse suse10affected
redhat rhel5.6affected
ubuntu ubuntu10.04affected
linux linux-kernelaffected3.2.65

References

CWEs

CWE-269

Verify integrity in audit chain (admin only). AS-IS.