LOW · 2.1

CVE-2014-9585

The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR p...

Vulnerability Description

The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:N/I:P/A:N
Confidentiality
NONE
Integrity
PARTIAL
Availability
NONE

Affected Products

VendorProductVersions
LinuxLinux Kernel<= 3.18.2
RedhatEnterprise Linux Aus6.6
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Eus6.6
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Aus7.3
RedhatEnterprise Linux Server Eus7.1
RedhatEnterprise Linux Server Tus6.6
RedhatEnterprise Linux Workstation6.0
OpensuseEvergreen11.4
OpensuseOpensuse13.1
SuseLinux Enterprise Desktop12
SuseLinux Enterprise Real Time Extension11
SuseLinux Enterprise Server11
SuseLinux Enterprise Software Development Kit12
SuseLinux Enterprise Workstation Extension12
FedoraprojectFedora21
DebianDebian Linux7.0
CanonicalUbuntu Linux12.04

References

FAQ

What is CVE-2014-9585?

CVE-2014-9585 is a vulnerability with a CVSS score of 2.1 (LOW). The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR p...

How severe is CVE-2014-9585?

CVE-2014-9585 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-9585?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Enterprise Linux Aus, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Eus, Redhat Enterprise Linux Server.