CVE-2014-4699
MEDIUM severity · CVSS 6.9 · CWE-362
6.9CVSS MEDIUM
Summary
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and fork system calls.
Impact & exploitability
Attack vectorLocal
Attack complexity—
Privileges required—
User interaction—
Confidentiality impact—
Integrity impact—
Availability impact—
Exploit probability (EPSS)2%
AV:L/AC:M/Au:N/C:C/I:C/A:C
Affected products we track (1)
Recommendation
Apply the vendor fix in your normal patch cycle. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=b9cd18de4db3c9ffa7e17b0dc0ca99ed5aa4d43aAdvisory
- http://linux.oracle.com/errata/ELSA-2014-0924.htmlAdvisory
- http://linux.oracle.com/errata/ELSA-2014-3047.htmlAdvisory
- http://linux.oracle.com/errata/ELSA-2014-3048.htmlAdvisory
- http://openwall.com/lists/oss-security/2014/07/05/4Advisory
- http://openwall.com/lists/oss-security/2014/07/08/16Advisory
- http://openwall.com/lists/oss-security/2014/07/08/5Advisory
- http://packetstormsecurity.com/files/127573/Linux-Kernel-ptrace-sysret-Local-Privilege-Escalation.htmlAdvisory