Linux Kernel CVE Statistics

8 Linux Kernel CVEs in December 2014

Full month · Source: NIST NVD

November 2014 January 2015

In December 2014, 8 Linux kernel CVEs were published, sourced from the NIST National Vulnerability Database. Of these, 4 were rated High severity and 1 Medium. No CVEs from this month have been confirmed as actively exploited via the CISA KEV catalog. December's 8 CVEs represent 6% of all 2014 Linux kernel CVEs , down from November's 24 (a 67% month-over-month decrease) .

8
Total CVEs
0
Critical
4
High
1
Medium
3
Low
0
KEV Exploited
All CVEs — December 2014 8 CVEs
All (8) Critical (0) High (4) Medium (1) Low (3)
CVE ID Package Severity CVSS Published Description
CVE-2014-9322 linux High 7.8 2014-12-17 arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack …
CVE-2014-4323 linux High 7.5 2014-12-12 The mdp_lut_hw_update function in drivers/video/msm/mdp.c in the MDP display driver for the Linux kernel 3.x, as used i…
CVE-2014-7300 linux High 7.2 2014-12-25 GNOME Shell 3.14.x before 3.14.1, when the Screen Lock feature is used, does not limit the aggregate memory consumption…
CVE-2014-4322 linux High 7.2 2014-12-24 drivers/misc/qseecom.c in the QSEECOM driver for the Linux kernel 3.x, as used in Qualcomm Innovation Center (QuIC) And…
CVE-2014-9420 linux Medium 4.9 2014-12-26 The rock_continue function in fs/isofs/rock.c in the Linux kernel through 3.18.1 does not restrict the number of Rock R…
CVE-2014-8134 linux Low 3.3 2014-12-12 The paravirt_ops_setup function in arch/x86/kernel/kvm.c in the Linux kernel through 3.18 uses an improper paravirt_ena…
CVE-2014-9419 linux Low 2.1 2014-12-26 The __switch_to function in arch/x86/kernel/process_64.c in the Linux kernel through 3.18.1 does not ensure that Thread…
CVE-2014-8133 linux Low 2.1 2014-12-17 arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local …

Frequently Asked Questions

How many Linux kernel CVEs were published in December 2014?

8 Linux kernel CVEs were published in December 2014, sourced from the NIST National Vulnerability Database. Of these, 0 were rated Critical severity, 4 High, and 1 Medium.

How does December 2014 compare to other months?

December 2014's 8 CVEs represent 6% of all 2014 Linux kernel CVEs. Compared to November's 24 CVEs, this was a 67% decrease month-over-month. View the full 2014 breakdown →

November 2014 2014 statistics January 2015