Security readout for executives and security teams
Plain-English summary
CVE-2014-0972 is a legacy Android/Linux graphics driver flaw. A local user or app could abuse the Qualcomm kgsl GPU driver to change memory mapping behavior and write to arbitrary memory locations. The source bundle does not name exact products, versions, patches, or active exploitation.
Executive priority
Treat this as a high-priority legacy mobile and embedded exposure where affected Qualcomm-based devices remain in use. Urgency depends on whether unsupported devices are still deployed and whether users can run untrusted local apps.
Technical view
The kgsl graphics driver in Linux kernel 3.x, as used in QuIC Android contributions for MSM devices and other products, did not properly prevent write access to IOMMU context registers. A crafted GPU command stream could select a custom page table and enable arbitrary memory writes.
Likely exposure
Likely exposure is limited to legacy Android/MSM devices or other products using affected Linux 3.x kgsl graphics driver code. The provided sources do not identify exact OEM devices, firmware builds, CPEs, or maintained product versions.
Exploitation context
The described attacker is local. The bundle does not support claims of remote exploitation, active exploitation, KEV listing, or exploit availability. The impact is still serious because arbitrary memory writes in a kernel graphics path can undermine device integrity.
Researcher notes
Evidence is sparse: CVE data describes the vulnerable driver behavior but provides no CVSS, CWE, affected-version matrix, fixed-version details, or exploit telemetry. Validate against OEM kernel trees and Qualcomm/CodeAurora advisory material before declaring exposure or closure.
Mitigation direction
- Check Qualcomm/OEM guidance for CVE-2014-0972 and apply available kernel or firmware updates.
- Prioritize replacement of unsupported Android/MSM devices using legacy Linux 3.x kgsl drivers.
- Restrict sideloading and untrusted local app installation on potentially affected devices.
- Track this CVE in mobile asset risk reviews for legacy Qualcomm-based devices.
Validation and detection
- Identify devices using Linux 3.x kernels with the kgsl graphics driver.
- Map affected devices to OEM firmware and kernel security update status.
- Review inventory for legacy MSM-based Android devices without current vendor support.
- Confirm app installation controls reduce local untrusted execution paths.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CVE-2014-0972 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- Unknown
- CVSS
- Not scored
- Known Exploited
- No
- Published
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS and timeline data
No CVSS vectors or timeline events were available in the normalized CVE source material.
Source materials
- CVE List V5 sourceCVE List V5
- https://www.codeaurora.org/projects/security-advisories/unprivileged-gpu-command-streams-can-change-the-iommu-page-table-cve-2014-0972CVE reference · x_refsource_CONFIRM
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
