CVE-2014-4699

CVSS v2.0 6.9 (Medium)
69% Progress
EPSS 0.04 % (0th)
0.04% Progress
Affected Products 3
Advisories 50

The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and fork system calls.

Weaknesses
CWE-362
Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition')
CVE Status
PUBLISHED
CNA
MITRE
Published Date
2014-07-09 11:07:03
(10 years ago)
Updated Date
2024-02-16 20:27:25
(7 months ago)

Affected Products

Loading...
Loading...
Loading...

Configuration #1

    CPE23 From Up To
  Linux Kernel from 2.6.17 version and prior 3.2.61 version cpe:2.3:o:linux:linux_kernel >= 2.6.17 < 3.2.61
  Linux Kernel from 3.3 version and prior 3.4.97 version cpe:2.3:o:linux:linux_kernel >= 3.3 < 3.4.97
  Linux Kernel from 3.5 version and prior 3.10.47 version cpe:2.3:o:linux:linux_kernel >= 3.5 < 3.10.47
  Linux Kernel from 3.11 version and prior 3.12.25 version cpe:2.3:o:linux:linux_kernel >= 3.11 < 3.12.25
  Linux Kernel from 3.13 version and prior 3.14.11 version cpe:2.3:o:linux:linux_kernel >= 3.13 < 3.14.11
  Linux Kernel from 3.15 version and prior 3.15.4 version cpe:2.3:o:linux:linux_kernel >= 3.15 < 3.15.4

Configuration #2

    CPE23 From Up To
  Debian Linux 7.0 cpe:2.3:o:debian:debian_linux:7.0

Configuration #3

    CPE23 From Up To
  Canonical Ubuntu Linux 10.04 cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-
  Canonical Ubuntu Linux 12.04 cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm
  Canonical Ubuntu Linux 13.10 cpe:2.3:o:canonical:ubuntu_linux:13.10
  Canonical Ubuntu Linux 14.04 cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...
Loading...