PT-2014-1859 · Centos+5 · Centos+5
CVE-2014-9322
·
Publicado
2014-12-07
·
Atualizado
2025-09-29
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Red Hat Enterprise Linux kernel versions prior to 3.17.5
CentOS kernel versions prior to 3.17.5
Description
The vulnerability in the Linux kernel can lead to a disruption of confidentiality, integrity, and availability of protected information. It can be exploited locally or remotely, depending on the specific package and version. The issue is related to the handling of faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.
Recommendations
For Red Hat Enterprise Linux kernel versions prior to 3.17.5, update to a version 3.17.5 or later.
For CentOS kernel versions prior to 3.17.5, update to a version 3.17.5 or later.
As a temporary workaround, consider restricting access to the vulnerable kernel packages until a patch is available.
Exploit
Correção
Improper Privilege Management
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Identificadores relacionados
Produtos afetados
Alt Linux
Centos
Linux Kernel
Red Hat
Suse
Ubuntu