cbcvebase.
CVE-2014-3534
published 2014-08-01

CVE-2014-3534: arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in…

PriorityP431high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.47%
38.1th percentile
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a crafted application that makes a ptrace system call.

Affected

12 ranges
VendorProductVersion rangeFixed in
debiandebian_linux
debianlinux< linux 3.14.13-2 (bookworm)linux 3.14.13-2 (bookworm)
linuxlinux_kernel< 3.2.623.2.62
linuxlinux_kernel>= 0 < 3.14.13-23.14.13-2
linuxlinux_kernel>= 0 < 3.14.13-23.14.13-2
linuxlinux_kernel>= 0 < 3.14.13-23.14.13-2
linuxlinux_kernel>= 0 < 3.14.13-23.14.13-2
linuxlinux_kernel>= 3.11 < 3.12.273.12.27
linuxlinux_kernel>= 3.13 < 3.14.153.14.15
linuxlinux_kernel>= 3.15 < 3.15.83.15.8
linuxlinux_kernel>= 3.3 < 3.4.1013.4.101
linuxlinux_kernel>= 3.5 < 3.10.513.10.51

CVSS provenance

nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.