CVE-2014-7822

Linux Kernel < 3.15.8 - Access Control

Title source: rule

Description

The implementation of certain splice_write file operations in the Linux kernel before 3.16 does not enforce a restriction on the maximum size of a single file, which allows local users to cause a denial of service (system crash) or possibly have unspecified other impact via a crafted splice system call, as demonstrated by use of a file descriptor associated with an ext4 filesystem.

Exploits (1)

exploitdb WORKING POC
by Emeric Nasi · cdoslinux
https://www.exploit-db.com/exploits/36743

References (21)

... and 1 more

Scores

EPSS 0.0038
EPSS Percentile 59.6%

Details

CWE
CWE-264
Status published
Products (1)
linux/linux_kernel < 3.15.8
Published Mar 16, 2015
Tracked Since Feb 18, 2026