UBUNTU-CVE-2014-3534

    Dashboard / Vulnerabilities / UBUNTU-CVE-2014-3534

    UBUNTU-CVE-2014-3534

    Published: 1 Aug 2014Last Modified: 16 Jul 2025
    Upstream:

    Summary:

    Details: arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a crafted application that makes a ptrace system call.

    Affected packages

    Package

    Name: linux-lts-utopic

    Purl: pkg:deb/ubuntu/[email protected]~14.04.2?arch=source&distro=trusty

    Affected ranges

    Type: ECOSYSTEM

    Events:

    Introduced- 0
    Fixed -3.16.0-25.33~14.04.2

    Affected versions

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High
    UBUNTU-CVE-2014-3534 | CVE-DB