Access Restriction Bypass Affecting torvalds/linux package, versions [,3.10.102)


Severity

Recommended
0.0
high
0
10

CVSS assessment made by Snyk's Security Team. Learn more

Threat Intelligence

EPSS
0.08% (24th percentile)

Do your applications use this vulnerable package?

In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.

Test your applications
  • Snyk IDSNYK-UNMANAGED-TORVALDSLINUX-3006185
  • published26 Jan 2022
  • disclosed6 Aug 2016
  • creditUnknown

Introduced: 6 Aug 2016

CVE-2014-9870  (opens in a new tab)
CWE-264  (opens in a new tab)

How to fix?

Upgrade torvalds/linux to version 3.10.102 or higher.

Overview

Affected versions of this package are vulnerable to Access Restriction Bypass. The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05 on Nexus 5 and 7 (2013) devices, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, aka Android internal bug 28749743 and Qualcomm internal bug CR561044.

CVSS Base Scores

version 3.1