PT-2014-8424 · Linux+5 · Linux Kernel+5

Published

2014-12-08

·

Updated

2023-02-13

·

CVE-2014-8134

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions prior to 3.19
Description The issue makes it easier for guest OS users to bypass the ASLR protection mechanism. This is achieved via a crafted application that reads a 16-bit value, exploiting the improper paravirt enabled setting for KVM guest kernels in the paravirt ops setup function.
Recommendations For Linux kernel versions prior to 3.19, update to version 3.19 or later to resolve the issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2014-2452
ALT-PU-2015-1794
CESA-2016_0855
CVE-2014-8134
DLA-155-1
MGASA-2015-0006
MGASA-2015-0075
MGASA-2015-0076
MGASA-2015-0077
MGASA-2015-0078
OPENSUSE-SU-2015_0713-1
OPENSUSE-SU-2015_0714-1
RHSA-2016:0855
RHSA-2016_0855
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2441-1
USN-2442-1
USN-2443-1
USN-2444-1
USN-2445-1
USN-2446-1
USN-2447-1
USN-2447-2
USN-2448-1
USN-2464-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu