CVE-2014-4508
arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled and the sep CPU feature flag is set, allows local users to cause a denial of service (OOPS and system crash) via an invalid syscall…
Does this matter?
Lower severity and a low EPSS score (0.41%). Track it; it rarely justifies an emergency change on its own.
Description
arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled and the sep CPU feature flag is set, allows local users to cause a denial of service (OOPS and system crash) via an invalid syscall number, as demonstrated by number 1000.
- CVSS 2.0
- 4.7 MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
- EPSS
- 0.41% probability · 35th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-189
- Affected
- linux/linux kernel · canonical/ubuntu linux
- Source
- cve@mitre.org
References
- http://article.gmane.org/gmane.linux.kernel/1726110Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlMailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2014/06/20/1Mailing List, Third Party Advisory
- http://secunia.com/advisories/58964Third Party Advisory
- http://secunia.com/advisories/60564Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/06/20/10Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/11/12/3
- http://www.securityfocus.com/bid/68126Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2334-1Third Party Advisory
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.61Vendor Advisory
- http://article.gmane.org/gmane.linux.kernel/1726110Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlMailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2014/06/20/1Mailing List, Third Party Advisory
- http://secunia.com/advisories/58964Third Party Advisory
- http://secunia.com/advisories/60564Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/06/20/10Mailing List, Third Party Advisory
- http://www.openwall.com/lists/oss-security/2020/11/12/3
- http://www.securityfocus.com/bid/68126Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2334-1Third Party Advisory
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.2.61Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.