CVE-2014-9322: Canonical Ubuntu Linux
High severity, CVSS 7.8. EPSS: 1.5% chance of exploitation in the next 30 days.
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.
Affected products
- Canonical Ubuntu Linux: version 10.04 only
- Google Android: version 6.0 only; version 6.0.1 only
- Linux Linux Kernel: before 3.2.65 (fixed in 3.2.65); from 3.3, before 3.4.106 (fixed in 3.4.106); from 3.5, before 3.10.62 (fixed in 3.10.62); from 3.11, before 3.12.35 (fixed in 3.12.35); from 3.13, before 3.14.26 (fixed in 3.14.26); from 3.15, before 3.16.35 (fixed in 3.16.35); …
- Opensuse Evergreen: version 11.4 only
- Red Hat Enterprise Linux Eus: version 5.6 only
- Suse Suse Linux Enterprise Server: version 10 only
Published 2014-12-17. Last modified 2026-06-17.