Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-9322

33
FAUCET Score

CVE-2014-9322 is a local privilege escalation vulnerability in the Linux kernel (before 3.17.5) affecting various distributions like Canonical, Google, and Red Hat. It stems from improper handling of Stack Segment (SS) faults during IRET instructions, allowing local users to gain elevated privileges. With a CVSS score of 7.8 (High), it has a low attack complexity and can lead to full compromise of confidentiality, integrity, and availability. While not actively exploited in the wild (not in KEV or Hot List), public exploit code exists on ExploitDB, and it has garnered significant community discussion and media coverage.

Impacted Technologies

VendorProductVersion(s)CPE
< 3.2.65CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.3, < 3.4.106CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.5, < 3.10.62CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.11, < 3.12.35CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
>= 3.13, < 3.14.26CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.1

7.8HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
1.8
Impact Score
5.9
CvssVersion
3.1

Exploit Intelligence

EPSS Score
1.45%
Probability of exploitation in next 30 days
EPSS Percentile
70.6%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
ExploitDB: EDB-44205 · Jul 24, 2017
This CVE's current EPSS score of 0.0145 is in the 95th percentile among its peer group of 17,061 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.

Media Mentions

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (14)

github_advisorypatch availablevia nvd_reference
View patch
googlepatch availablevia nvd_reference
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 4 Extended Lifecycle SupportFixed in: kernel-0:2.6.9-106.EL
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel-0:2.6.18-400.1.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.6 Long LifeFixed in: kernel-0:2.6.18-238.54.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 5.9 Extended Update SupportFixed in: kernel-0:2.6.18-348.29.1.el5
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.2 Advanced Update SupportFixed in: kernel-0:2.6.32-220.57.1.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.4 Extended Update SupportFixed in: kernel-0:2.6.32-358.51.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6.5 Extended Update SupportFixed in: kernel-0:2.6.32-431.40.2.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-123.13.2.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-0:3.10.58-rt62.60.el6rt
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-504.3.3.el6
View patch
redhatpatch availablevia nvd_reference
View patch
redhatno patchvia redhat_api
Product: Red Hat Enterprise Linux Extended Update Support 5.6Fixed in: kernel

Vendor Advisories (1)

redhatCVE-2014-9322Important

kernel: x86: local privesc due to bad_iret and paranoid entry incompatibility

Dec 15, 2014

References

git.kernel.org
lists.opensuse.org / opensuse-security-announce/2015-03/msg00025.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-04/msg00015.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-04/msg00020.html
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
marc.info
Mailing ListThird Party Advisory
osvdb.org / show/osvdb/115919
Broken Link
rhn.redhat.com / errata/RHSA-2014-1998.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-2008.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-2028.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2014-2031.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-0009.html
Third Party Advisory
bugzilla.redhat.com / show_bug.cgi
Issue TrackingPatchThird Party Advisory
secunia.com / advisories/62336
Broken Link
github.com / torvalds/linux/commit/6f442be2fb22be02cafa606f1769fa1e6f894441
PatchThird Party Advisory
help.joyent.com / entries/98788667-Security-Advisory-ZDI-CAN-3263-ZDI-CAN-3284-and-ZDI-CAN-3364-Vulnerabilities
Permissions RequiredThird Party Advisory
source.android.com / security/bulletin/2016-04-02.html
PatchThird Party Advisory
kernel.org / pub/linux/kernel/v3.x/ChangeLog-3.17.5
Mailing ListPatchVendor Advisory
exploit-db.com / exploits/36266
ExploitThird Party AdvisoryVDB Entry
openwall.com / lists/oss-security/2014/12/15/6
Mailing ListPatchThird Party Advisory
ubuntu.com / usn/USN-2491-1
Third Party Advisory
zerodayinitiative.com / advisories/ZDI-16-170
Third Party AdvisoryVDB Entry