VYPR
High severity7.8NVD Advisory· Published Jun 13, 2017· Updated May 13, 2026

CVE-2014-9965

CVE-2014-9965

Description

A vulnerability in parsing SCM calls in the Linux kernel used in CAF Android releases enables local privilege escalation.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A vulnerability in parsing SCM calls in the Linux kernel used in CAF Android releases enables local privilege escalation.

Vulnerability

The vulnerability resides in the parsing of socket control messages (SCM) in the Linux kernel as used in all Android releases from Code Aurora Forum (CAF). The issue allows improper handling of specially crafted SCM calls, potentially leading to memory corruption. This affects all Android versions derived from CAF kernels prior to the June 2017 security update.

Exploitation

To exploit this vulnerability, an attacker must have local access to the device and the ability to invoke SCM calls (e.g., via an application). No additional privileges are required initially. The attacker crafts a malicious SCM call that triggers a kernel-level memory corruption due to insufficient validation.

Impact

Successful exploitation results in elevation of privilege from a normal application context to kernel-level code execution. The attacker can gain full control over the device, including the ability to execute arbitrary code with kernel privileges.

Mitigation

The vulnerability was addressed in the Android security bulletin for June 2017 [1]. Users should apply the latest security patch level provided by their device manufacturer. If a patch is not available, no known workaround exists.

AI Insight generated on May 22, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2
  • cpe:2.3:o:google:android:*:*:*:*:*:*:*:*
  • Qualcomm, Inc./All Qualcomm productsv5
    Range: All Android releases from CAF using the Linux kernel

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.