CVE-2014-9803: Critical severity Linux Linux Kernel vulnerability
arch/arm64/include/asm/pgtable.h in the Linux kernel before 3.15-rc5-next-20140519, as used in Android before 2016-07-05 on Nexus 5X and 6P devices, mishandles execute-only pages, which allows attackers to gain privileges via a crafted application, aka Android internal bug 28557020.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9803?
CVE-2014-9803 has a medium severity rating due to its potential to allow privilege escalation in affected devices.
How do I fix CVE-2014-9803?
To fix CVE-2014-9803, update the Linux kernel to version 3.15 or later and ensure that your Android device is updated to version 6.0.2 or above.
Which versions are affected by CVE-2014-9803?
CVE-2014-9803 affects Linux kernel versions up to 3.15 and Android versions up to 6.0.1.
What types of devices are impacted by CVE-2014-9803?
CVE-2014-9803 primarily impacts Nexus 5X and 6P devices running vulnerable versions of Android.
Can CVE-2014-9803 be exploited remotely?
CVE-2014-9803 requires a crafted application to exploit, which means it typically cannot be exploited remotely without user interaction.