CVE-2014-4322

Linux kernel 3.x - Memory Corruption

Title source: llm

Description

drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) Android contributions for MSM devices and other products, does not validate certain offset, length, and base values within an ioctl call, which allows attackers to gain privileges or cause a denial of service (memory corruption) via a crafted application.

Exploits (5)

exploitdb WORKING POC
by retme · clocalandroid
https://www.exploit-db.com/exploits/35711
nomisec WORKING POC 93 stars
by retme7 · poc
https://github.com/retme7/CVE-2014-4322_poc
nomisec WORKING POC 24 stars
by laginimaineb · poc
https://github.com/laginimaineb/cve-2014-4322
nomisec WORKING POC 1 stars
by askk · poc
https://github.com/askk/CVE-2014-4322_adaptation
nomisec WORKING POC
by koozxcv · poc
https://github.com/koozxcv/CVE-2014-4322

Scores

EPSS 0.0345
EPSS Percentile 87.6%

Details

CWE
CWE-787
Status published
Products (1)
linux/linux_kernel 3.0.0 - 3.18.1
Published Dec 24, 2014
Tracked Since Feb 18, 2026