Vulnerability Description
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and fork system calls.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | >= 2.6.17, < 3.2.61 |
| Debian | Debian Linux | 7.0 |
| Canonical | Ubuntu Linux | 10.04 |
Related Weaknesses (CWE)
References
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=Broken LinkThird Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-0924.htmlThird Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-3047.htmlThird Party Advisory
- http://linux.oracle.com/errata/ELSA-2014-3048.htmlThird Party Advisory
- http://openwall.com/lists/oss-security/2014/07/05/4Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2014/07/08/16Mailing ListThird Party Advisory
- http://openwall.com/lists/oss-security/2014/07/08/5Mailing ListThird Party Advisory
- http://packetstormsecurity.com/files/127573/Linux-Kernel-ptrace-sysret-Local-PriExploitThird Party AdvisoryVDB Entry
- http://secunia.com/advisories/59633Third Party Advisory
- http://secunia.com/advisories/59639Third Party Advisory
- http://secunia.com/advisories/59654Third Party Advisory
- http://secunia.com/advisories/60220Third Party Advisory
- http://secunia.com/advisories/60380Third Party Advisory
- http://secunia.com/advisories/60393Third Party Advisory
- http://www.debian.org/security/2014/dsa-2972Third Party Advisory
FAQ
What is CVE-2014-4699?
CVE-2014-4699 is a vulnerability with a CVSS score of 6.9 (MEDIUM). The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows l...
How severe is CVE-2014-4699?
CVE-2014-4699 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-4699?
Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Debian Debian Linux, Canonical Ubuntu Linux.