PT-2014-1943 · Canonical+5 · Linux-Image-3.2.0+6

Published

2014-12-25

·

Updated

2018-01-05

·

CVE-2014-9419

CVSS v2.0

10

High

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.18.1 linux-image-3.2.0
Description The issue concerns a problem in the Linux kernel that makes it easier for local users to bypass the ASLR protection mechanism. This is due to the switch to function not ensuring that Thread Local Storage (TLS) descriptors are loaded before proceeding with other steps. Additionally, there are multiple vulnerabilities in the linux-image-3.2.0 package of the Ubuntu operating system that can lead to violations of confidentiality, integrity, and availability of protected information, and these can be exploited remotely.
Recommendations For Linux kernel versions prior to 3.18.1, update to a version 3.18.1 or later to resolve the issue. For linux-image-3.2.0, consider upgrading to a newer version of the linux-image package to mitigate the risk of exploitation. As a temporary workaround, consider restricting access to sensitive information and implementing additional security measures to minimize the risk of exploitation until a patch is available.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALT-PU-2015-1018
ALT-PU-2015-1794
BDU:2015-09846
CESA-2015_1081
CESA-2015_2152
CVE-2014-9419
DSA-3128-1
MGASA-2015-0006
MGASA-2015-0075
MGASA-2015-0076
MGASA-2015-0077
MGASA-2015-0078
OPENSUSE-SU-2015_0713-1
OPENSUSE-SU-2015_0714-1
OPENSUSE-SU-2016_0301-1
RHSA-2015:1081
RHSA-2015:2152
RHSA-2015:2411
RHSA-2015_1081
RHSA-2015_2152
RHSA-2015_2411
SUSE-RU-2015:0621-1
SUSE-SU-2015:0529-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2515-1
USN-2516-1
USN-2516-2
USN-2516-3
USN-2517-1
USN-2518-1
USN-2541-1
USN-2542-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu
Linux-Image-3.2.0