PT-2014-8293 · Linux+4 · Linux Kernel+4

Robert Święcki

·

Published

2014-11-10

·

Updated

2023-02-13

·

CVE-2014-7825

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 3.17.2
Description The issue allows local users to cause a denial of service or bypass the ASLR protection mechanism via a crafted application. This is due to the kernel's failure to properly handle private syscall numbers during use of the perf subsystem, leading to an out-of-bounds read and OOPS.
Recommendations For Linux kernel versions through 3.17.2, update to a version that contains a fix for this issue. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Out of bounds Read

Weakness Enumeration

Related Identifiers

ALT-PU-2014-2361
ALT-PU-2014-2362
CESA-2015_0290
CESA-2015_0864
CVE-2014-7825
RHSA-2014:1943
RHSA-2015:0290
RHSA-2015:0864
RHSA-2015_0290
RHSA-2015_0864
USN-2443-1
USN-2444-1
USN-2445-1
USN-2446-1
USN-2447-1
USN-2447-2
USN-2448-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Ubuntu