PT-2014-1943 · Canonical+5 · Linux-Image-3.2.0+6
Published
2014-12-25
·
Updated
2018-01-05
·
CVE-2014-9419
CVSS v2.0
10
High
| Vector | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 3.18.1
linux-image-3.2.0
Description
The issue concerns a problem in the Linux kernel that makes it easier for local users to bypass the ASLR protection mechanism. This is due to the switch to function not ensuring that Thread Local Storage (TLS) descriptors are loaded before proceeding with other steps. Additionally, there are multiple vulnerabilities in the linux-image-3.2.0 package of the Ubuntu operating system that can lead to violations of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations
For Linux kernel versions prior to 3.18.1, update to a version 3.18.1 or later to resolve the issue.
For linux-image-3.2.0, consider upgrading to a newer version of the linux-image package to mitigate the risk of exploitation.
As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of exploitation until a patch is available.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu
Linux-Image-3.2.0