cbcvebase.
CVE-2014-7843
published 2014-11-30

CVE-2014-7843: The __clear_user function in arch/arm64/lib/clear_user.S in the Linux kernel before 3.17.4 on the ARM64 platform allows local users to cause a denial of…

PriorityP413medium4.9CVSS 2.0
AVLACLAuNCNINAC
EPSS
0.37%
30.4th percentile
The __clear_user function in arch/arm64/lib/clear_user.S in the Linux kernel before 3.17.4 on the ARM64 platform allows local users to cause a denial of service (system crash) by reading one byte beyond a /dev/zero page boundary.

Affected

7 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.16.7-ckt2-1 (bookworm)linux 3.16.7-ckt2-1 (bookworm)
linuxlinux_kernel<= 3.17.3
linuxlinux_kernel>= 0 < 3.16.7-ckt2-13.16.7-ckt2-1
linuxlinux_kernel>= 0 < 3.16.7-ckt2-13.16.7-ckt2-1
linuxlinux_kernel>= 0 < 3.16.7-ckt2-13.16.7-ckt2-1
linuxlinux_kernel>= 0 < 3.16.7-ckt2-13.16.7-ckt2-1
linuxlinux_kernel>= 0 < 3.13.0-44.733.13.0-44.73

CVSS provenance

nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.0MEDIUM
vendor_ubuntu5.0MEDIUM
vendor_debian4.9MEDIUM
vendor_redhat4.9MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.