CVE-2014-3534

CVSS v2.0 7.2 (High)
72% Progress
EPSS 0.04 % (5th)
0.04% Progress
Affected Products 2
Advisories 25

arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a crafted application that makes a ptrace system call.

Weaknesses
CWE-269
Improper Privilege Management
CVE Status
PUBLISHED
CNA
Red Hat, Inc.
Published Date
2014-08-01 11:13:09
(10 years ago)
Updated Date
2023-10-03 16:59:01
(11 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel prior 3.2.62 version cpe:2.3:o:linux:linux_kernel < 3.2.62
  Linux Kernel from 3.3 version and prior 3.4.101 version cpe:2.3:o:linux:linux_kernel >= 3.3 < 3.4.101
  Linux Kernel from 3.5 version and prior 3.10.51 version cpe:2.3:o:linux:linux_kernel >= 3.5 < 3.10.51
  Linux Kernel from 3.11 version and prior 3.12.27 version cpe:2.3:o:linux:linux_kernel >= 3.11 < 3.12.27
  Linux Kernel from 3.13 version and prior 3.14.15 version cpe:2.3:o:linux:linux_kernel >= 3.13 < 3.14.15
  Linux Kernel from 3.15 version and prior 3.15.8 version cpe:2.3:o:linux:linux_kernel >= 3.15 < 3.15.8

Configuration #2

    CPE23 From Up To
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...