CVE-2014-9322
N/A
N/A
Summary
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| n/a | n/a | n/a | affected |
Weaknesses
- n/a
ADP Enrichment
CVE Program Container
Additional References
- http://www.ubuntu.com/usn/USN-2491-1
- http://marc.info/?l=bugtraq&m=142722450701342&w=2
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.17.5
- https://bugzilla.redhat.com/show_bug.cgi?id=1172806
- http://rhn.redhat.com/errata/RHSA-2015-0009.html
- http://marc.info/?l=bugtraq&m=142722544401658&w=2
- https://help.joyent.com/entries/98788667-Security-Advisory-ZDI-CAN-3263-ZDI-CAN-3284-and-ZDI-CAN-3364-Vulnerabilities
- http://www.zerodayinitiative.com/advisories/ZDI-16-170
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html
- http://rhn.redhat.com/errata/RHSA-2014-2008.html
- https://github.com/torvalds/linux/commit/6f442be2fb22be02cafa606f1769fa1e6f894441
- http://secunia.com/advisories/62336
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6f442be2fb22be02cafa606f1769fa1e6f894441
- http://source.android.com/security/bulletin/2016-04-02.html
- http://rhn.redhat.com/errata/RHSA-2014-1998.html
- http://www.exploit-db.com/exploits/36266
- http://rhn.redhat.com/errata/RHSA-2014-2028.html
- http://rhn.redhat.com/errata/RHSA-2014-2031.html
- http://osvdb.org/show/osvdb/115919
- http://www.openwall.com/lists/oss-security/2014/12/15/6
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html
References
- http://www.ubuntu.com/usn/USN-2491-1
- http://marc.info/?l=bugtraq&m=142722450701342&w=2
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.html
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.17.5
- https://bugzilla.redhat.com/show_bug.cgi?id=1172806
- http://rhn.redhat.com/errata/RHSA-2015-0009.html
- http://marc.info/?l=bugtraq&m=142722544401658&w=2
- https://help.joyent.com/entries/98788667-Security-Advisory-ZDI-CAN-3263-ZDI-CAN-3284-and-ZDI-CAN-3364-Vulnerabilities
- http://www.zerodayinitiative.com/advisories/ZDI-16-170
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html
- http://rhn.redhat.com/errata/RHSA-2014-2008.html
- https://github.com/torvalds/linux/commit/6f442be2fb22be02cafa606f1769fa1e6f894441
- http://secunia.com/advisories/62336
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6f442be2fb22be02cafa606f1769fa1e6f894441
- http://source.android.com/security/bulletin/2016-04-02.html
- http://rhn.redhat.com/errata/RHSA-2014-1998.html
- http://www.exploit-db.com/exploits/36266
- http://rhn.redhat.com/errata/RHSA-2014-2028.html
- http://rhn.redhat.com/errata/RHSA-2014-2031.html
- http://osvdb.org/show/osvdb/115919
- http://www.openwall.com/lists/oss-security/2014/12/15/6
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.