kernel: x86: local privesc due to bad_iret and paranoid entry incompatibility
Published Dec 17, 2014
7.8
HIGHCVSS 3.1
EPSS 1.54%
Description
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.
Affected products
No data.
Configuration 1
- < 3.2.65
- ≥ 3.3 · < 3.4.106
- ≥ 3.5 · < 3.10.62
- ≥ 3.11 · < 3.12.35
- ≥ 3.13 · < 3.14.26
- ≥ 3.15 · < 3.16.35
- ≥ 3.17 · < 3.17.5
Configuration 2
- 5.6
Configuration 3
- 10.04
Configuration 4
- 11.4
- 10
No data.
Red Hat Enterprise Linux 4 Extended Lifecycle Support
kernel-0:2.6.9-106.EL
Fixed · RHSA-2015:0009
Red Hat Enterprise Linux 5
kernel-0:2.6.18-400.1.1.el5
Fixed · RHSA-2014:2008
Red Hat Enterprise Linux 5.6 Long Life
kernel-0:2.6.18-238.54.1.el5
Fixed · RHSA-2014:2031
Red Hat Enterprise Linux 5.9 Extended Update Support
kernel-0:2.6.18-348.29.1.el5
Fixed · RHSA-2014:2029
Red Hat Enterprise Linux 6
kernel-0:2.6.32-504.3.3.el6
Fixed · RHSA-2014:1997
Red Hat Enterprise Linux 6.2 Advanced Update Support
kernel-0:2.6.32-220.57.1.el6
Fixed · RHSA-2014:2028
Red Hat Enterprise Linux 6.4 Extended Update Support
kernel-0:2.6.32-358.51.2.el6
Fixed · RHSA-2014:2030
Red Hat Enterprise Linux 6.5 Extended Update Support
kernel-0:2.6.32-431.40.2.el6
Fixed · RHSA-2014:2009
Red Hat Enterprise Linux 7
kernel-0:3.10.0-123.13.2.el7
Fixed · RHSA-2014:2010
Red Hat Enterprise MRG 2
kernel-rt-0:3.10.58-rt62.60.el6rt
Fixed · RHSA-2014:1998
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 Extended Lifecycle Support | kernel-0:2.6.9-106.EL | Fixed | RHSA-2015:0009 |
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-400.1.1.el5 | Fixed | RHSA-2014:2008 |
| Red Hat Enterprise Linux 5.6 Long Life | kernel-0:2.6.18-238.54.1.el5 | Fixed | RHSA-2014:2031 |
| Red Hat Enterprise Linux 5.9 Extended Update Support | kernel-0:2.6.18-348.29.1.el5 | Fixed | RHSA-2014:2029 |
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-504.3.3.el6 | Fixed | RHSA-2014:1997 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | kernel-0:2.6.32-220.57.1.el6 | Fixed | RHSA-2014:2028 |
| Red Hat Enterprise Linux 6.4 Extended Update Support | kernel-0:2.6.32-358.51.2.el6 | Fixed | RHSA-2014:2030 |
| Red Hat Enterprise Linux 6.5 Extended Update Support | kernel-0:2.6.32-431.40.2.el6 | Fixed | RHSA-2014:2009 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-123.13.2.el7 | Fixed | RHSA-2014:2010 |
| Red Hat Enterprise MRG 2 | kernel-rt-0:3.10.58-rt62.60.el6rt | Fixed | RHSA-2014:1998 |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue does affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 4, 5, 6, and 7, and Red Hat Enterprise MRG 2. Future Linux kernel updates for the respective releases will address this issue.
Metrics
No CVSS v4.0 score for this CVE.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:C/I:C/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (14 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 1.54% (0.01540) | 73.98th | v5 (v2026.06.15) |
| Jun 15, 2026 | 1.50% (0.01504) | 70.91th | v5 (v2026.06.15) |
| Mar 30, 2025 | 5.03% (0.05031) | 88.75th | v4 (v2025.03.14) |
| Mar 29, 2025 | 7.70% (0.07699) | 86.24th | v4 (v2025.03.14) |
| Mar 28, 2025 | 5.03% (0.05031) | 88.77th | v4 (v2025.03.14) |
| Mar 27, 2025 | 7.70% (0.07699) | 90.70th | v4 (v2025.03.14) |
| Mar 20, 2025 | 5.03% (0.05031) | 88.86th | v4 (v2025.03.14) |
| Mar 19, 2025 | 7.70% (0.07699) | 90.83th | v4 (v2025.03.14) |
| Mar 17, 2025 | 5.03% (0.05031) | 89.01th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00042) | 0.34th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.04% (0.00042) | 0.50th | v3 (v2023.03.01) |
| Mar 6, 2023 | 3.82% (0.03821) | 85.56th | v2 (v2022.01.01) |
| Apr 1, 2022 | 3.82% (0.03821) | 84.08th | v2 (v2022.01.01) |
| Feb 4, 2022 | 3.82% (0.03821) | 67.27th | v2 (v2022.01.01) |
References (25)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6f442be2fb22be02cafa606f1769fa1e6f894441 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html vendor-advisoryx_refsource_SUSEMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=142722450701342&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://marc.info/?l=bugtraq&m=142722544401658&w=2 vendor-advisoryx_refsource_HPMailing ListThird Party Advisory
- http://osvdb.org/show/osvdb/115919 vdb-entryx_refsource_OSVDBBroken Link
- http://rhn.redhat.com/errata/RHSA-2014-1998.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-2008.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-2028.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-2031.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0009.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://secunia.com/advisories/62336 third-party-advisoryx_refsource_SECUNIABroken Link
- http://source.android.com/security/bulletin/2016-04-02.html x_refsource_CONFIRMPatchThird Party Advisory
- http://www.exploit-db.com/exploits/36266 exploitx_refsource_EXPLOIT-DBThird Party AdvisoryVDB Entry
- http://www.openwall.com/lists/oss-security/2014/12/15/6 mailing-listx_refsource_MLISTMailing ListPatchThird Party Advisory
- http://www.ubuntu.com/usn/USN-2491-1 vendor-advisoryx_refsource_UBUNTUThird Party Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-16-170 x_refsource_MISCThird Party AdvisoryVDB Entry
- https://access.redhat.com/security/cve/CVE-2014-9322 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1172806 x_refsource_CONFIRMIssue TrackingPatchThird Party Advisory
- https://github.com/torvalds/linux/commit/6f442be2fb22be02cafa606f1769fa1e6f894441 x_refsource_CONFIRMPatchThird Party Advisory
- https://help.joyent.com/entries/98788667-Security-Advisory-ZDI-CAN-3263-ZDI-CAN-3284-and-ZDI-CAN-3364-Vulnerabilities x_refsource_CONFIRMPermissions RequiredThird Party Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2014-9322
- https://www.cve.org/CVERecord?id=CVE-2014-9322
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.17.5 x_refsource_CONFIRMMailing ListPatchVendor Advisory
Change history (0)
No recorded changes yet.