CVE-2014-9914: Google Android

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Race condition in the ip4_datagram_release_cb function in net/ipv4/datagram.c in the Linux kernel before 3.15.2 allows local users to gain privileges or cause a denial of service (use-after-free) by leveraging incorrect expectations about locking during multithreaded access to internal data structures for IPv4 UDP sockets.

Affected products

  • Google Android: up to and including 7.1.1
  • Linux Linux Kernel: from 3.7.8, before 3.10.45 (fixed in 3.10.45); from 3.11, before 3.12.23 (fixed in 3.12.23); from 3.13, before 3.14.9 (fixed in 3.14.9); from 3.15, before 3.15.2 (fixed in 3.15.2)

Published 2017-02-07. Last modified 2026-06-17.