CVE-2014-9710

medium
Published 2015-05-27 · Modified 2026-05-06
CVSS v3
CVSS v2
6.9
VIR risk
6.9

Description

The Btrfs implementation in the Linux kernel before 3.19 does not ensure that the visible xattr state is consistent with a requested replacement, which allows local users to bypass intended ACL settings and gain privileges via standard filesystem operations (1) during an xattr-replacement time window, related to a race condition, or (2) after an xattr-replacement attempt that fails because the data does not fit.

Predictions

Exploit likelihood
20%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: debian — https://security-tracker.debian.org/tracker/CVE-2014-9710

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — https://github.com/torvalds/linux/commit/5f5bc6b1e2d5a6f827bc860ef2dc5b6f365d1339

vendor Authored 2026-05-27

Vendor advisory: secalert@redhat.com — http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5f5bc6b1e2d5a6f827bc860ef2dc5b6f365d1339

OS impact

OSVersionStatusFixed in
debian debianbookwormfixed3.16.7-ckt9-1
debian debianbullseyefixed3.16.7-ckt9-1
debian debianforkyfixed3.16.7-ckt9-1
debian debiansidfixed3.16.7-ckt9-1
debian debiantrixiefixed3.16.7-ckt9-1
linux linux-kernelaffected3.10.83

References

CWEs

CWE-362

Verify integrity in audit chain (admin only). AS-IS.