PT-2015-4295 · Linux+5 · Linux Kernel+5

Published

2015-01-09

·

Updated

2020-05-21

·

CVE-2014-9585

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Linux kernel versions through 3.18.2
Description The issue concerns the vdso addr function in the Linux kernel, which does not properly choose memory locations for the vDSO area. This makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.
Recommendations For Linux kernel versions through 3.18.2, update to a version that contains a fix for this issue.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

ALT-PU-2015-1058
ALT-PU-2015-1794
CESA-2015_1081
CESA-2015_1778
CVE-2014-9585
DLA-155-1
DSA-3170-1
MGASA-2015-0070
MGASA-2015-0075
MGASA-2015-0076
MGASA-2015-0077
MGASA-2015-0078
OPENSUSE-SU-2015_0713-1
OPENSUSE-SU-2015_0714-1
RHSA-2015:1081
RHSA-2015:1778
RHSA-2015:1787
RHSA-2015:1788
RHSA-2015_1081
RHSA-2015_1778
RHSA-2015_1788
SUSE-RU-2015:0621-1
SUSE-SU-2015:0481-1
SUSE-SU-2015:0581-1
SUSE-SU-2015:0652-1
SUSE-SU-2015:0736-1
SUSE-SU-2015:1174-1
SUSE-SU-2015:1376-1
USN-2513-1
USN-2514-1
USN-2515-1
USN-2516-1
USN-2516-2
USN-2516-3
USN-2517-1
USN-2518-1

Affected Products

Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu