CVE-2014-5332 describes a race condition in the NVMap component of the NVIDIA Tegra Linux Kernel 3.10, allowing local users to gain privileges through a crafted NVMAP_IOC_CREATE IOCTL call, which can lead to a use-after-free error. This vulnerability has a CVSS score of 6.9, indicating a medium severity with local attack vector, medium attack complexity, and high impact on confidentiality, integrity, and availability. While there is no evidence of active exploitation or public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered some community attention, including a Reddit discussion and a Hackernews article detailing its use to escape the Chrome sandbox.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
3.10CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:3.10:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.