CVE-2014-9940: Use After Free
Last updated 24 July 2024
Other sources
The regulatorenagpiofree function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2014-9940?
CVE-2014-9940 is a vulnerability in the Linux kernel that allows local users to gain privileges or cause a denial of service through a use-after-free issue in the regulator_ena_gpio_free function.
How severe is CVE-2014-9940?
CVE-2014-9940 has a severity rating of 7 (high).
Which software versions are affected by CVE-2014-9940?
Ubuntu Linux versions 3.13.0-123.172 and Linux kernel versions up to 3.19 are affected by CVE-2014-9940.
How can I fix CVE-2014-9940?
To fix CVE-2014-9940, you should update your Linux kernel to version 3.19 or higher.
Where can I find more information about CVE-2014-9940?
You can find more information about CVE-2014-9940 on the following references: [http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=60a2362f769cf549dc466134efe71c8bf9fbaaba](http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=60a2362f769cf549dc466134efe71c8bf9fbaaba), [https://github.com/torvalds/linux/commit/60a2362f769cf549dc466134efe71c8bf9fbaaba](https://github.com/torvalds/linux/commit/60a2362f769cf549dc466134efe71c8bf9fbaaba), [https://source.android.com/security/bulletin/2017-05-01](https://source.android.com/security/bulletin/2017-05-01)