CVE-2014-9888

HIGH

Linux Kernel < 3.12.9 - Privilege Escalation via Executable DMA Mappings

Title source: llm
STIX 2.1

Description

arch/arm/mm/dma-mapping.c in the Linux kernel before 3.13 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not prevent executable DMA mappings, which might allow local users to gain privileges via a crafted application, aka Android internal bug 28803642 and Qualcomm internal bug CR642735.

Scores

CVSS v3 7.8
EPSS 0.0040
EPSS Percentile 32.4%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-264
Status published
Products (1)
linux/linux_kernel < 3.12.9
Published Aug 06, 2016
Tracked Since Feb 18, 2026