CVE-2014-9322
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (1.54%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.54% probability · 73th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-269
- Affected
- linux/linux kernel · redhat/enterprise linux eus · canonical/ubuntu linux · opensuse/evergreen · suse/suse linux enterprise server · google/android
- Source
- cve@mitre.org
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6f442be2fb22be02cafa606f1769fa1e6f894441
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=142722450701342&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=142722544401658&w=2Mailing List, Third Party Advisory
- http://osvdb.org/show/osvdb/115919Broken Link
- http://rhn.redhat.com/errata/RHSA-2014-1998.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-2008.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-2028.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2014-2031.htmlThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2015-0009.htmlThird Party Advisory
- http://secunia.com/advisories/62336Broken Link
- http://source.android.com/security/bulletin/2016-04-02.htmlPatch, Third Party Advisory
- http://www.exploit-db.com/exploits/36266Exploit, Third Party Advisory, VDB Entry
- http://www.openwall.com/lists/oss-security/2014/12/15/6Mailing List, Patch, Third Party Advisory
- http://www.ubuntu.com/usn/USN-2491-1Third Party Advisory
- http://www.zerodayinitiative.com/advisories/ZDI-16-170Third Party Advisory, VDB Entry
- https://bugzilla.redhat.com/show_bug.cgi?id=1172806Issue Tracking, Patch, Third Party Advisory
- https://github.com/torvalds/linux/commit/6f442be2fb22be02cafa606f1769fa1e6f894441Patch, Third Party Advisory
- https://help.joyent.com/entries/98788667-Security-Advisory-ZDI-CAN-3263-ZDI-CAN-3284-and-ZDI-CAN-3364-VulnerabilitiesPermissions Required, Third Party Advisory
- https://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.17.5Mailing List, Patch, Vendor Advisory
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=6f442be2fb22be02cafa606f1769fa1e6f894441
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.htmlMailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=142722450701342&w=2Mailing List, Third Party Advisory
- http://marc.info/?l=bugtraq&m=142722544401658&w=2Mailing List, Third Party Advisory
- http://osvdb.org/show/osvdb/115919Broken Link
- http://rhn.redhat.com/errata/RHSA-2014-1998.htmlThird Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.