CVE-2014-9870: Google Android

High severity, CVSS 7.8. EPSS: 1% chance of exploitation in the next 30 days.

The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, aka Android internal bug 28749743 and Qualcomm internal bug CR561044.

Affected products

  • Google Android: up to and including 6.0.1
  • Linux Linux Kernel: up to and including 3.10.101

Published 2016-08-06. Last modified 2026-06-17.