PT-2016-3503 · Linux+1 · Linux Kernel+1

Published

2015-06-03

·

Updated

2020-11-17

·

CVE-2014-9410

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions 3.x
Description The issue concerns a function in the MSM-VFE31 driver that does not properly validate a certain id value. This allows attackers to potentially gain privileges or cause a denial of service, resulting in memory corruption, by making a crafted ioctl call through an application.
Recommendations For Linux kernel version 3.x, update to a version that includes the fix for this issue, as the vulnerable function needs to be patched to properly validate the id value.

Exploit

Fix

DoS

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1485
ALT-PU-2015-1849
CVE-2014-9410

Affected Products

Alt Linux
Linux Kernel