Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2014-9585

11
FAUCET Score

CVE-2014-9585 describes a vulnerability in the Linux kernel (through version 3.18.2) where the vdso_addr function fails to properly randomize the vDSO memory location, making it easier for local users to bypass Address Space Layout Randomization (ASLR). This flaw affects various Linux distributions including Canonical, Debian, Fedora, openSUSE, Red Hat, and SUSE. The vulnerability has a CVSS score of 2.1, indicating low severity, with a local attack vector and low attack complexity, primarily impacting integrity by facilitating ASLR bypass. There is no direct impact on confidentiality or availability. There is no evidence of active exploitation, nor are there publicly available exploit modules in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage for this CVE are minimal, suggesting a low level of public awareness and concern.

Impacted Technologies

VendorProductVersion(s)CPE
<= 3.18.2CPE matchmatch criteria
cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*
6.6CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_aus:6.6:*:*:*:*:*:*:*
6.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_desktop:6.0:*:*:*:*:*:*:*
7.0CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_desktop:7.0:*:*:*:*:*:*:*
6.6CPE matchmatch criteria
cpe:2.3:o:redhat:enterprise_linux_eus:6.6:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 2.0

2.1LOW

AV:L/AC:L/Au:N/C:N/I:P/A:N

Confidentiality Impact
NONE
Integrity Impact
PARTIAL
Availability Impact
NONE
Access Vector
LOCAL
Access Complexity
LOW
Authentication
NONE
Exploitability Score
3.9
Impact Score
2.9
CvssVersion
2.0

Exploit Intelligence

EPSS Score
0.56%
Probability of exploitation in next 30 days
EPSS Percentile
43.1%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0056 is in the 79th percentile among its peer group of 2,096 CVEs.

Social Chatter

No social media mentions found for this CVE.

The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.6 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (5)

redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 6Fixed in: kernel-0:2.6.32-504.23.4.el6
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-rt-0:3.10.0-229.14.1.rt56.141.13.el7_1
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise Linux 7Fixed in: kernel-0:3.10.0-229.14.1.el7
View patch
redhatpatch availablevia redhat_api
Product: Red Hat Enterprise MRG 2Fixed in: kernel-rt-1:3.10.0-229.rt56.161.el6rt
View patch
redhatend of lifevia redhat_api
Product: Red Hat Enterprise Linux 5Fixed in: kernel

Vendor Advisories (1)

redhatCVE-2014-9585Low

kernel: ASLR bruteforce possible for vdso library

Dec 11, 2014

References

git.kernel.org
git.kernel.org
lists.fedoraproject.org / pipermail/package-announce/2015-January/148480.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-01/msg00035.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-03/msg00010.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-03/msg00025.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-04/msg00000.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-04/msg00009.html
Mailing ListThird Party Advisory
lists.opensuse.org / opensuse-security-announce/2015-04/msg00015.html
Mailing ListThird Party Advisory
rhn.redhat.com / errata/RHSA-2015-1081.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1778.html
Third Party Advisory
rhn.redhat.com / errata/RHSA-2015-1787.html
Third Party Advisory
v0ids3curity.blogspot.in / 2014/12/return-to-vdso-using-elf-auxiliary.html
Broken Link
debian.org / security/2015/dsa-3170
Third Party Advisory
mandriva.com / security/advisories
Third Party Advisory
openwall.com / lists/oss-security/2014/12/09/10
ExploitMailing ListThird Party Advisory
openwall.com / lists/oss-security/2015/01/09/8
Mailing ListThird Party Advisory
securityfocus.com / bid/71990
Third Party AdvisoryVDB Entry
ubuntu.com / usn/USN-2513-1
Third Party Advisory
ubuntu.com / usn/USN-2514-1
Third Party Advisory
ubuntu.com / usn/USN-2515-1
Third Party Advisory
ubuntu.com / usn/USN-2516-1
Third Party Advisory
ubuntu.com / usn/USN-2517-1
Third Party Advisory
ubuntu.com / usn/USN-2518-1
Third Party Advisory