CVE-2014-9940
published 2017-05-02CVE-2014-9940: The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of…
PriorityP430high7CVSS 3.1
AVLACHPRNUIRSUCHIHAH
EPSS
1.61%
73.6th percentile
The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.0.2-1 (bookworm) | linux 4.0.2-1 (bookworm) |
| android | <= 7.1.1 | — | |
| android | — | — | |
| linux | linux_kernel | < 3.16.45 | 3.16.45 |
| linux | linux_kernel | — | — |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 3.13.0-123.172 | 3.13.0-123.172 |
| linux | linux_kernel | >= 3.17 < 3.18.52 | 3.18.52 |
CVSS provenance
nvdv3.17.0HIGHCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.07.6HIGHAV:N/AC:H/Au:N/C:C/I:C/A:C
osv7.0HIGH
vendor_debian7.0LOW
vendor_msrc7.0HIGH
vendor_redhat7.0HIGH
vendor_ubuntu7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-06-29·CVSS 7.0
CVE-2014-9940 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN 3335-1 fixed a vulnerability in the Linux kernel. However, that
fix introduced regressions for some Java applications. This update
addresses the issue. We apologize for the inconvenience.
It was discovered that a use-after-free vulnerability in the core voltage
regulator driver of the Linux kernel. A local attacker could use this to
cause a denial of service or possibly execute arbitrary code.
(CVE-2014-9940)
It was discovered that a buffer overflow existed in the trace subsystem in
the Linux kernel. A privileged local attacker could use this to execute
arbitrary code. (CVE-2017-0605)
Roee Hay discovered that the parallel port printer driver in the Linux
kernel did not properly bou
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-06-29·CVSS 7.0
CVE-2014-9940 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN 3343-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
USN 3335-2 fixed a vulnerability in the Linux kernel. However, that
fix introduced regressions for some Java applications. This update
addresses the issue. We apologize for the inconvenience.
It was discovered that a use-after-free vulnerability in the core voltage
regulator driver of the Linux kernel. A local attacker could use this to
cause a denial of service or possibly execute arbitrary code.
(CVE-2014-9940)
It was discovered that a buffer overflow existed in
Microsoft
The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted appli
vendor_msrc·2017-05-09·CVSS 7.0
CVE-2014-9940 [HIGH] CWE-416 The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted appli
The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will upd
Android
CVE-2014-9940: Android Security Bulletin 2017-05-01
CVE: CVE-2014-9940
Severity: HIGH
References: A-35399757
Upstream kernel
vendor_android·2017-05-01·CVSS 7.0
CVE-2014-9940 [HIGH] CVE-2014-9940: Android Security Bulletin 2017-05-01
CVE: CVE-2014-9940
Severity: HIGH
References: A-35399757
Upstream kernel
Android Security Bulletin 2017-05-01
CVE: CVE-2014-9940
Severity: HIGH
References: A-35399757
Upstream kernel
Red Hat
kernel: Use-after-free in the regulator_ena_gpio_free function
vendor_redhat·2014-12-04·CVSS 7.0
CVE-2014-9940 [HIGH] CWE-416 kernel: Use-after-free in the regulator_ena_gpio_free function
kernel: Use-after-free in the regulator_ena_gpio_free function
The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.
The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.
Statement: This issue does not affects the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6, 7 and Red Hat Enterprise MRG 2, as the code with the flaw is not present or is not built and so is not shipped in the products listed.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red
Debian
CVE-2014-9940: linux - The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux ke...
vendor_debian·2014·CVSS 7.0
CVE-2014-9940 [HIGH] CVE-2014-9940: linux - The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux ke...
The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-1)
forky: resolved (fixed in 4.0.2-1)
sid: resolved (fixed in 4.0.2-1)
trixie: resolved (fixed in 4.0.2-1)
GHSA
GHSA-p8qv-rw4q-gfw4: The regulator_ena_gpio_free function in drivers/regulator/core
ghsa_unreviewed·2022-05-17
CVE-2014-9940 [HIGH] CWE-416 GHSA-p8qv-rw4q-gfw4: The regulator_ena_gpio_free function in drivers/regulator/core
The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.
OSV
linux vulnerabilities
osv·2017-06-29·CVSS 7.0
CVE-2014-9940 [HIGH] linux vulnerabilities
linux vulnerabilities
USN 3335-1 fixed a vulnerability in the Linux kernel. However, that
fix introduced regressions for some Java applications. This update
addresses the issue. We apologize for the inconvenience.
It was discovered that a use-after-free vulnerability in the core voltage
regulator driver of the Linux kernel. A local attacker could use this to
cause a denial of service or possibly execute arbitrary code.
(CVE-2014-9940)
It was discovered that a buffer overflow existed in the trace subsystem in
the Linux kernel. A privileged local attacker could use this to execute
arbitrary code. (CVE-2017-0605)
Roee Hay discovered that the parallel port printer driver in the Linux
kernel did not properly bounds check passed arguments. A local attacker
with write access to the kernel com
OSV
CVE-2014-9940: The regulator_ena_gpio_free function in drivers/regulator/core
osv·2017-05-02·CVSS 7.0
CVE-2014-9940 [HIGH] CVE-2014-9940: The regulator_ena_gpio_free function in drivers/regulator/core
The regulator_ena_gpio_free function in drivers/regulator/core.c in the Linux kernel before 3.19 allows local users to gain privileges or cause a denial of service (use-after-free) via a crafted application.
No detection rules found.
No public exploits indexed.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=60a2362f769cf549dc466134efe71c8bf9fbaabahttp://www.debian.org/security/2017/dsa-3945http://www.securityfocus.com/bid/98195https://github.com/torvalds/linux/commit/60a2362f769cf549dc466134efe71c8bf9fbaabahttps://source.android.com/security/bulletin/2017-05-01http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=60a2362f769cf549dc466134efe71c8bf9fbaabahttp://www.debian.org/security/2017/dsa-3945http://www.securityfocus.com/bid/98195https://github.com/torvalds/linux/commit/60a2362f769cf549dc466134efe71c8bf9fbaabahttps://source.android.com/security/bulletin/2017-05-01
2017-05-02
Published