CVE-2014-7826
published 2014-11-10CVE-2014-7826: kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which…
PriorityP337high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.59%
44.2th percentile
kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via a crafted application.
Affected
15 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 3.16.7-ckt2-1 (bookworm) | linux 3.16.7-ckt2-1 (bookworm) |
| linux | linux_kernel | >= 0 < 3.16.7-ckt2-1 | 3.16.7-ckt2-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt2-1 | 3.16.7-ckt2-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt2-1 | 3.16.7-ckt2-1 |
| linux | linux_kernel | >= 0 < 3.16.7-ckt2-1 | 3.16.7-ckt2-1 |
| linux | linux_kernel | >= 0 < 3.13.0-43.72 | 3.13.0-43.72 |
| linux | linux_kernel | >= 2.6.32 < 3.2.65 | 3.2.65 |
| linux | linux_kernel | >= 3.11 < 3.12.33 | 3.12.33 |
| linux | linux_kernel | >= 3.13 < 3.14.24 | 3.14.24 |
| linux | linux_kernel | >= 3.15 < 3.16.35 | 3.16.35 |
| linux | linux_kernel | >= 3.17 < 3.17.3 | 3.17.3 |
| linux | linux_kernel | >= 3.3 < 3.4.106 | 3.4.106 |
| linux | linux_kernel | >= 3.5 < 3.10.60 | 3.10.60 |
| opensuse | evergreen | — | — |
| suse | suse_linux_enterprise_server | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Ubuntu
Linux kernel regression
vendor_ubuntu·2014-12-19·CVSS 7.5
[HIGH] Linux kernel regression
Title: Linux kernel regression
Summary: USN-2448-1 introduced a regression in the Linux kernel.
USN-2448-1 fixed vulnerabilities in the Linux kernel. Due to an unrelated
regression TCP Throughput drops to zero for several drivers after upgrading.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private
Ubuntu
Linux kernel (Utopic HWE) regression
vendor_ubuntu·2014-12-19·CVSS 7.5
[HIGH] Linux kernel (Utopic HWE) regression
Title: Linux kernel (Utopic HWE) regression
Summary: USN-2447-1 introduced a regression in the Linux kernel.
USN-2447-1 fixed vulnerabilities in the Linux kernel. Due to an unrelated
regression TCP Throughput drops to zero for several drivers after upgrading.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly h
Ubuntu
Linux kernel (Utopic HWE) vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.5
CVE-2014-3673 [HIGH] Linux kernel (Utopic HWE) vulnerabilities
Title: Linux kernel (Utopic HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered that the Linux kernel does not properly handle
faults associated with the Stack Segment (SS) register in the x86
architecture. A local attacker could exploit this flaw to gain
administrative privileges. (CVE-2014-9322)
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly han
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.5
CVE-2014-3673 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered that the Linux kernel does not properly handle
faults associated with the Stack Segment (SS) register in the x86
architecture. A local attacker could exploit this flaw to gain
administrative privileges. (CVE-2014-9322)
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private s
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.5
CVE-2014-3673 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered that the Linux kernel does not properly handle
faults associated with the Stack Segment (SS) register in the x86
architecture. A local attacker could exploit this flaw to gain
administrative privileges. (CVE-2014-9322)
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private s
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.8
CVE-2014-7825 [HIGH] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered that the Linux kernel does not properly handle
faults associated with the Stack Segment (SS) register in the x86
architecture. A local attacker could exploit this flaw to gain
administrative privileges. (CVE-2014-9322)
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private s
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.5
CVE-2014-3673 [HIGH] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Andy Lutomirski discovered that the Linux kernel does not properly handle
faults associated with the Stack Segment (SS) register in the x86
architecture. A local attacker could exploit this flaw to gain
administrative privileges. (CVE-2014-9322)
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly han
Ubuntu
Linux kernel (OMAP4) vulnerabilities
vendor_ubuntu·2014-12-12·CVSS 7.8
CVE-2014-7825 [HIGH] Linux kernel (OMAP4) vulnerabilities
Title: Linux kernel (OMAP4) vulnerabilities
Summary: Several security issues were fixed in the kernel.
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private syscall
numbers. A local user could exploit this flaw to cause a denial of service
(OOPS). (CVE-2014-7826)
Rabin Vincent, Robert Swiecki, Russell Kinglaw discovered a flaw in how the
perf subsystem of the Linux kernel handles private systecall numbers. A
local user could exploit this to cause a denial of service (OOPS) or bypass
ASLR protections via a crafted application. (CVE-2014-7825)
A null pointer dereference flaw was discovered in the the Linux kernel's
SCTP implementation when ASCONF is used. A remote attacker could exploit
this flaw to cause a d
Red Hat
kernel: insufficient syscall number validation in perf and ftrace subsystems
vendor_redhat·2014-11-07·CVSS 7.8
CVE-2014-7825 [HIGH] kernel: insufficient syscall number validation in perf and ftrace subsystems
kernel: insufficient syscall number validation in perf and ftrace subsystems
kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the perf subsystem, which allows local users to cause a denial of service (out-of-bounds read and OOPS) or bypass the ASLR protection mechanism via a crafted application.
An out-of-bounds memory access flaw, CVE-2014-7825, was found in the syscall tracing functionality of the Linux kernel's perf subsystem. A local, unprivileged user could use this flaw to crash the system. Additionally, an out-of-bounds memory access flaw, CVE-2014-7826, was found in the syscall tracing functionality of the Linux kernel's ftrace subsystem. On a system with ftrace syscall tracing enabled, a local, unpriv
Red Hat
kernel: insufficient syscall number validation in perf and ftrace subsystems
vendor_redhat·2014-11-07·CVSS 7.8
CVE-2014-7826 [HIGH] kernel: insufficient syscall number validation in perf and ftrace subsystems
kernel: insufficient syscall number validation in perf and ftrace subsystems
kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via a crafted application.
An out-of-bounds memory access flaw, CVE-2014-7825, was found in the syscall tracing functionality of the Linux kernel's perf subsystem. A local, unprivileged user could use this flaw to crash the system. Additionally, an out-of-bounds memory access flaw, CVE-2014-7826, was found in the syscall tracing functionality of the Linux kernel's ftrace subsystem. On a system with ftrace syscall tracing enabled, a local, unprivileged user could u
Debian
CVE-2014-7826: linux - kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not proper...
vendor_debian·2014·CVSS 7.8
CVE-2014-7826 [HIGH] CVE-2014-7826: linux - kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not proper...
kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via a crafted application.
Scope: local
bookworm: resolved (fixed in 3.16.7-ckt2-1)
bullseye: resolved (fixed in 3.16.7-ckt2-1)
forky: resolved (fixed in 3.16.7-ckt2-1)
sid: resolved (fixed in 3.16.7-ckt2-1)
trixie: resolved (fixed in 3.16.7-ckt2-1)
GHSA
GHSA-5jvp-w9hf-v844: kernel/trace/trace_syscalls
ghsa_unreviewed·2022-05-13
CVE-2014-7826 [HIGH] CWE-476 GHSA-5jvp-w9hf-v844: kernel/trace/trace_syscalls
kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via a crafted application.
OSV
linux-lts-utopic regression
osv·2014-12-19·CVSS 7.5
[HIGH] linux-lts-utopic regression
linux-lts-utopic regression
USN-2447-1 fixed vulnerabilities in the Linux kernel. Due to an unrelated
regression TCP Throughput drops to zero for several drivers after upgrading.
This update fixes the problem.
We apologize for the inconvenience.
Original advisory details:
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private syscall
numbers. A local user could exploit this flaw to cause a den
OSV
linux vulnerabilities
osv·2014-12-12·CVSS 7.5
CVE-2014-9322 [HIGH] linux vulnerabilities
linux vulnerabilities
Andy Lutomirski discovered that the Linux kernel does not properly handle
faults associated with the Stack Segment (SS) register in the x86
architecture. A local attacker could exploit this flaw to gain
administrative privileges. (CVE-2014-9322)
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private syscall
numbers. A local user could exploit this flaw to cause a denial of
OSV
linux-lts-utopic vulnerabilities
osv·2014-12-12·CVSS 7.5
CVE-2014-9322 [HIGH] linux-lts-utopic vulnerabilities
linux-lts-utopic vulnerabilities
Andy Lutomirski discovered that the Linux kernel does not properly handle
faults associated with the Stack Segment (SS) register in the x86
architecture. A local attacker could exploit this flaw to gain
administrative privileges. (CVE-2014-9322)
An information leak in the Linux kernel was discovered that could leak the
high 16 bits of the kernel stack address on 32-bit Kernel Virtual Machine
(KVM) paravirt guests. A user in the guest OS could exploit this leak to
obtain information that could potentially be used to aid in attacking the
kernel. (CVE-2014-8134)
Rabin Vincent, Robert Swiecki, Russell King discovered that the ftrace
subsystem of the Linux kernel does not properly handle private syscall
numbers. A local user could exploit this flaw to cause a
OSV
CVE-2014-7826: kernel/trace/trace_syscalls
osv·2014-11-10·CVSS 7.8
CVE-2014-7826 [HIGH] CVE-2014-7826: kernel/trace/trace_syscalls
kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via a crafted application.
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2014-7825 CVE-2014-7826 kernel: insufficient syscall number validation in perf and ftrace subsystems
bugzilla·2014-11-07·CVSS 7.8
CVE-2014-7825 [HIGH] CVE-2014-7825 CVE-2014-7826 kernel: insufficient syscall number validation in perf and ftrace subsystems
CVE-2014-7825 CVE-2014-7826 kernel: insufficient syscall number validation in perf and ftrace subsystems
An out-of-bounds memory access flaw was found in the Linux kernel's perf and
ftrace subsystems.
On a system with syscall perf profiling on (CVE-2014-7825) an unprivileged local
user could use this flaw to crash the system.
On a system with ftrace syscall tracing on (CVE-2014-7826) an unprivileged local
user could use this flaw to crash the system or escalate their privileges on
the system.
References:
http://www.openwall.com/lists/oss-security/2014/11/06/11
Upstream fix:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=086ba77a6db00ed858ff07451bedee197df868c9
Acknowledgements:
Red Hat would like to thank Robert Święcki for reporting these issues.
Discus
Bugzilla
CVE-2014-7826 CVE-2014-7825 kernel: insufficient syscall number validation in perf and ftrace subsystems [fedora-all]
bugzilla·2014-11-07·CVSS 7.8
CVE-2014-7826 [HIGH] CVE-2014-7826 CVE-2014-7825 kernel: insufficient syscall number validation in perf and ftrace subsystems [fedora-all]
CVE-2014-7826 CVE-2014-7825 kernel: insufficient syscall number validation in perf and ftrace subsystems [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of Fedora.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=086ba77a6db00ed858ff07451bedee197df868c9http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1943.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0864.htmlhttp://www.openwall.com/lists/oss-security/2014/11/06/11http://www.securityfocus.com/bid/70971https://bugzilla.redhat.com/show_bug.cgi?id=1161565https://exchange.xforce.ibmcloud.com/vulnerabilities/98556https://github.com/torvalds/linux/commit/086ba77a6db00ed858ff07451bedee197df868c9http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=086ba77a6db00ed858ff07451bedee197df868c9http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlhttp://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlhttp://rhn.redhat.com/errata/RHSA-2014-1943.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0290.htmlhttp://rhn.redhat.com/errata/RHSA-2015-0864.htmlhttp://www.openwall.com/lists/oss-security/2014/11/06/11http://www.securityfocus.com/bid/70971https://bugzilla.redhat.com/show_bug.cgi?id=1161565https://exchange.xforce.ibmcloud.com/vulnerabilities/98556https://github.com/torvalds/linux/commit/086ba77a6db00ed858ff07451bedee197df868c9
2014-11-10
Published