CVE-2015-8967
published 2016-12-08CVE-2015-8967: arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the…
PriorityP336high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.83%
53.4th percentile
arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access.
Affected
10 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.0.2-1 (bookworm) | linux 4.0.2-1 (bookworm) |
| android | <= 7.0 | — | |
| android | — | — | |
| linux | linux_kernel | <= 3.18.54 | — |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 4.0.2-1 | 4.0.2-1 |
| linux | linux_kernel | >= 0 < 3.13.0-125.174 | 3.13.0-125.174 |
| linux | linux_kernel | 3.19 – 3.19.8 | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8LOW
vendor_redhat7.8HIGH
vendor_ubuntu5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-34c2-924w-2mw6: arch/arm64/kernel/sys
ghsa_unreviewed·2022-05-17
CVE-2015-8967 [HIGH] GHSA-34c2-924w-2mw6: arch/arm64/kernel/sys
arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access.
OSV
linux vulnerabilities
osv·2017-07-21·CVSS 5.5
CVE-2014-9900 [MEDIUM] linux vulnerabilities
linux vulnerabilities
It was discovered that the Linux kernel did not properly initialize a Wake-
on-Lan data structure. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2014-9900)
It was discovered that the Linux kernel did not properly restrict access to
/proc/iomem. A local attacker could use this to expose sensitive
information. (CVE-2015-8944)
It was discovered that a use-after-free vulnerability existed in the
performance events and counters subsystem of the Linux kernel for ARM64. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2015-8955)
It was discovered that the SCSI generic (sg) driver in the Linux kernel
contained a double-free vulnerability. A local attacker could use
OSV
CVE-2015-8967: arch/arm64/kernel/sys
osv·2016-12-08·CVSS 7.8
CVE-2015-8967 [HIGH] CVE-2015-8967: arch/arm64/kernel/sys
arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access.
Ubuntu
Linux kernel vulnerabilities
vendor_ubuntu·2017-07-21·CVSS 5.5
CVE-2014-9900 [MEDIUM] Linux kernel vulnerabilities
Title: Linux kernel vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
It was discovered that the Linux kernel did not properly initialize a Wake-
on-Lan data structure. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2014-9900)
It was discovered that the Linux kernel did not properly restrict access to
/proc/iomem. A local attacker could use this to expose sensitive
information. (CVE-2015-8944)
It was discovered that a use-after-free vulnerability existed in the
performance events and counters subsystem of the Linux kernel for ARM64. A
local attacker could use this to cause a denial of service (system crash)
or possibly execute arbitrary code. (CVE-2015-8955)
It was discovered that the SCSI generic (sg) driver in the
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities
vendor_ubuntu·2017-07-21·CVSS 5.5
CVE-2014-9900 [MEDIUM] Linux kernel (Trusty HWE) vulnerabilities
Title: Linux kernel (Trusty HWE) vulnerabilities
Summary: Several security issues were fixed in the Linux kernel.
USN-3360-1 fixed vulnerabilities in the Linux kernel for Ubuntu 14.04
LTS. This update provides the corresponding updates for the Linux
Hardware Enablement (HWE) kernel from Ubuntu 14.04 LTS for Ubuntu
12.04 ESM.
It was discovered that the Linux kernel did not properly initialize a Wake-
on-Lan data structure. A local attacker could use this to expose sensitive
information (kernel memory). (CVE-2014-9900)
It was discovered that the Linux kernel did not properly restrict access to
/proc/iomem. A local attacker could use this to expose sensitive
information. (CVE-2015-8944)
It was discovered that a use-after-free vulnerability existed in the
performance events and counters s
Red Hat
kernel: arm64: Strict page permission bypass
vendor_redhat·2016-12-08·CVSS 7.8
CVE-2015-8967 [HIGH] CWE-471 kernel: arm64: Strict page permission bypass
kernel: arm64: Strict page permission bypass
arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access.
A flaw in 'arch/arm64/kernel/sys.c' in the Linux kernel allows local users to bypass the 'strict page permissions' protection mechanism and modify the system-call table and, consequently, gain privileges by leveraging write access.
Statement: This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 as code with the flaw is not present in the products listed.
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and Red Hat Enterprise
Android
CVE-2015-8967: Android Security Bulletin 2016-12-01
CVE: CVE-2015-8967
Severity: HIGH
References: A-31703084
Upstream kernel
vendor_android·2016-12-01·CVSS 7.8
CVE-2015-8967 [HIGH] CVE-2015-8967: Android Security Bulletin 2016-12-01
CVE: CVE-2015-8967
Severity: HIGH
References: A-31703084
Upstream kernel
Android Security Bulletin 2016-12-01
CVE: CVE-2015-8967
Severity: HIGH
References: A-31703084
Upstream kernel
Debian
CVE-2015-8967: linux - arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to byp...
vendor_debian·2015·CVSS 7.8
CVE-2015-8967 [HIGH] CVE-2015-8967: linux - arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to byp...
arch/arm64/kernel/sys.c in the Linux kernel before 4.0 allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access.
Scope: local
bookworm: resolved (fixed in 4.0.2-1)
bullseye: resolved (fixed in 4.0.2-1)
forky: resolved (fixed in 4.0.2-1)
sid: resolved (fixed in 4.0.2-1)
trixie: resolved (fixed in 4.0.2-1)
No detection rules found.
No public exploits indexed.
Bugzilla
CVE-2015-8967 kernel: arm64: Strict page permission bypass
bugzilla·2016-12-13·CVSS 7.8
CVE-2015-8967 [HIGH] CVE-2015-8967 kernel: arm64: Strict page permission bypass
CVE-2015-8967 kernel: arm64: Strict page permission bypass
The flaw in the code in 'arch/arm64/kernel/sys.c' in the Linux kernel allows local users to bypass the "strict page permissions" protection mechanism and modify the system-call table, and consequently gain privileges, by leveraging write access.
Upstream fix:
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c623b33b4e9599c6ac5076f7db7369eb9869aa04
References:
http://source.android.com/security/bulletin/2016-12-01.html
https://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2015-8967
Discussion:
Statement:
This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5, 6 as code with the flaw is not present in the products listed.
This issue does not affect the Linux k
arXiv
Trusted Container Extensions for Container-based Confidential Computing
arxiv_fulltext·2022-05-11
Trusted Container Extensions for Container-based Confidential Computing
Trusted Container Extensions for Container-based Confidential Computing
draft
[1]
plain
Anonymous
[1]
camera
Ferdinand Brasser, Patrick Jauernig, Frederik Pustelnik,
Ahmad-Reza Sadeghi, Emmanuel Stapf
Technical University of Darmstadt, Germany
\ferdinand.brasser, patrick.jauernig, emmanuel.stapf\@sanctuary.dev
\ahmad.sadeghi\@trust.tu-darmstadt.de
## Abstract
Cloud computing has emerged as a corner stone of today's computing landscape. More and more customers who outsource their infrastructure benefit from the manageability, scalability and cost saving that come with cloud computing. Those benefits get amplified by the trend towards microservices. Instead of renting and maintaining full VMs, customers increasingly leverage container technologies, which come with a much more light
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c623b33b4e9599c6ac5076f7db7369eb9869aa04http://source.android.com/security/bulletin/2016-12-01.htmlhttp://www.securityfocus.com/bid/94680https://github.com/torvalds/linux/commit/c623b33b4e9599c6ac5076f7db7369eb9869aa04http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=c623b33b4e9599c6ac5076f7db7369eb9869aa04http://source.android.com/security/bulletin/2016-12-01.htmlhttp://www.securityfocus.com/bid/94680https://github.com/torvalds/linux/commit/c623b33b4e9599c6ac5076f7db7369eb9869aa04
2016-12-08
Published