CVE-2014-4508
Last modified
CVE-2014-4508 is a vulnerability of currently unknown severity. arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled and the sep CPU feature flag is set, allows local users to cause a denial of service (OOPS and system crash) via an invalid syscall number, as demonstrated by number 1000.. EPSS estimates a 0.41% chance of exploitation in the next 30 days.
Description
arch/x86/kernel/entry_32.S in the Linux kernel through 3.15.1 on 32-bit x86 platforms, when syscall auditing is enabled and the sep CPU feature flag is set, allows local users to cause a denial of service (OOPS and system crash) via an invalid syscall number, as demonstrated by number 1000.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Linux | Linux Kernel | <= 3.15.1 |
| Canonical | Ubuntu Linux | 12.04 |
References
- http://article.gmane.org/gmane.linux.kernel/1726110Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlMailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2014/06/20/1Mailing List, Third Party Advisory
- http://secunia.com/advisories/58964Third Party Advisory
- http://secunia.com/advisories/60564Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/06/20/10Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/68126Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2334-1Third Party Advisory
- http://article.gmane.org/gmane.linux.kernel/1726110Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.htmlMailing List, Third Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlMailing List, Third Party Advisory
- http://openwall.com/lists/oss-security/2014/06/20/1Mailing List, Third Party Advisory
- http://secunia.com/advisories/58964Third Party Advisory
- http://secunia.com/advisories/60564Third Party Advisory
- http://www.openwall.com/lists/oss-security/2014/06/20/10Mailing List, Third Party Advisory
- http://www.securityfocus.com/bid/68126Third Party Advisory, VDB Entry
- http://www.ubuntu.com/usn/USN-2334-1Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2014-4508?
How severe is CVE-2014-4508?
How do I fix CVE-2014-4508?
Are you affected by CVE-2014-4508?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
