CVE-2014-3534
published 2014-08-01CVE-2014-3534: arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in…
PriorityP431high7.2CVSS 2.0
AVLACLAuNCCICAC
EPSS
0.47%
38.1th percentile
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a crafted application that makes a ptrace system call.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | debian_linux | — | — |
| debian | linux | < linux 3.14.13-2 (bookworm) | linux 3.14.13-2 (bookworm) |
| linux | linux_kernel | < 3.2.62 | 3.2.62 |
| linux | linux_kernel | >= 0 < 3.14.13-2 | 3.14.13-2 |
| linux | linux_kernel | >= 0 < 3.14.13-2 | 3.14.13-2 |
| linux | linux_kernel | >= 0 < 3.14.13-2 | 3.14.13-2 |
| linux | linux_kernel | >= 0 < 3.14.13-2 | 3.14.13-2 |
| linux | linux_kernel | >= 3.11 < 3.12.27 | 3.12.27 |
| linux | linux_kernel | >= 3.13 < 3.14.15 | 3.14.15 |
| linux | linux_kernel | >= 3.15 < 3.15.8 | 3.15.8 |
| linux | linux_kernel | >= 3.3 < 3.4.101 | 3.4.101 |
| linux | linux_kernel | >= 3.5 < 3.10.51 | 3.10.51 |
CVSS provenance
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.2HIGH
vendor_debian7.2HIGH
vendor_redhat7.2HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Red Hat
kernel: s390: ptrace: insufficient sanitization when setting psw mask
vendor_redhat·2014-07-21·CVSS 7.2
CVE-2014-3534 [HIGH] CWE-697 kernel: s390: ptrace: insufficient sanitization when setting psw mask
kernel: s390: ptrace: insufficient sanitization when setting psw mask
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a crafted application that makes a ptrace system call.
It was found that Linux kernel's ptrace subsystem did not properly sanitize the address-space-control bits when the program-status word (PSW) was being set. On IBM S/390 systems, a local, unprivileged user could use this flaw to set address-space-control bits to the kernel space, and thus gain read and write access to kernel memory.
Statement: This issue did not affect the
Debian
CVE-2014-3534: linux - arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform...
vendor_debian·2014·CVSS 7.2
CVE-2014-3534 [HIGH] CVE-2014-3534: linux - arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform...
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a crafted application that makes a ptrace system call.
Scope: local
bookworm: resolved (fixed in 3.14.13-2)
bullseye: resolved (fixed in 3.14.13-2)
forky: resolved (fixed in 3.14.13-2)
sid: resolved (fixed in 3.14.13-2)
trixie: resolved (fixed in 3.14.13-2)
GHSA
GHSA-w2mc-q8r3-wc3h: arch/s390/kernel/ptrace
ghsa_unreviewed·2022-05-13
CVE-2014-3534 [HIGH] CWE-269 GHSA-w2mc-q8r3-wc3h: arch/s390/kernel/ptrace
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a crafted application that makes a ptrace system call.
OSV
CVE-2014-3534: arch/s390/kernel/ptrace
osv·2014-08-01·CVSS 7.2
CVE-2014-3534 [HIGH] CVE-2014-3534: arch/s390/kernel/ptrace
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a crafted application that makes a ptrace system call.
Kernel
s390/ptrace: fix PSW mask check
kernel_security·2014-06-23·CVSS 7.2
CVE-2014-3534 [HIGH] s390/ptrace: fix PSW mask check
s390/ptrace: fix PSW mask check
The PSW mask check of the PTRACE_POKEUSR_AREA command is incorrect.
The PSW_MASK_USER define contains the PSW_MASK_ASC bits, the ptrace
interface accepts all combinations for the address-space-control
bits. To protect the kernel space the PSW mask check in ptrace needs
to reject the address-space-control bit combination for home space.
Fixes CVE-2014-3534
Cc: [email protected]
Signed-off-by: Martin Schwidefsky
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-3534 kernel: s390: ptrace: insufficient sanitization when setting psw mask [fedora-all]
bugzilla·2014-07-23·CVSS 7.2
CVE-2014-3534 [HIGH] CVE-2014-3534 kernel: s390: ptrace: insufficient sanitization when setting psw mask [fedora-all]
CVE-2014-3534 kernel: s390: ptrace: insufficient sanitization when setting psw mask [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affects multiple sup
Bugzilla
CVE-2014-3534 kernel: s390: ptrace: insufficient sanitization when setting psw mask
bugzilla·2014-06-27·CVSS 7.2
CVE-2014-3534 [HIGH] CVE-2014-3534 kernel: s390: ptrace: insufficient sanitization when setting psw mask
CVE-2014-3534 kernel: s390: ptrace: insufficient sanitization when setting psw mask
It was found that Linux kernel's ptrace subsystem did not properly
sanitize psw mask value. On s390 systems, an unprivileged local user
could use this flaw to set address space control bits to kernel space
combination and thus gain read/write access to kernel memory.
Discussion:
Statement:
This issue did not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 and Red Hat Enterprise MRG 2.
---
Upstream patch:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=dab6cf55f81a6e16b8147aed9a843e1691dcd318
---
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1122612]
---
kernel-3.15.7-200.fc20 has been pushed to the Fedora 20 stable
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=dab6cf55f81a6e16b8147aed9a843e1691dcd318http://secunia.com/advisories/59790http://secunia.com/advisories/60351http://www.debian.org/security/2014/dsa-2992http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.15.8http://www.osvdb.org/109546http://www.securityfocus.com/bid/68940http://www.securitytracker.com/id/1030683https://bugzilla.redhat.com/show_bug.cgi?id=1114089https://exchange.xforce.ibmcloud.com/vulnerabilities/95069https://github.com/torvalds/linux/commit/dab6cf55f81a6e16b8147aed9a843e1691dcd318http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=dab6cf55f81a6e16b8147aed9a843e1691dcd318http://secunia.com/advisories/59790http://secunia.com/advisories/60351http://www.debian.org/security/2014/dsa-2992http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.15.8http://www.osvdb.org/109546http://www.securityfocus.com/bid/68940http://www.securitytracker.com/id/1030683https://bugzilla.redhat.com/show_bug.cgi?id=1114089https://exchange.xforce.ibmcloud.com/vulnerabilities/95069https://github.com/torvalds/linux/commit/dab6cf55f81a6e16b8147aed9a843e1691dcd318
2014-08-01
Published