UBUNTU-CVE-2014-9322
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-9322
UBUNTU-CVE-2014-9322
Summary:
Details: arch/x86/kernel/entry_64.S in the Linux kernel before 3.17.5 does not properly handle faults associated with the Stack Segment (SS) segment register, which allows local users to gain privileges by triggering an IRET instruction that leads to access to a GS Base address from the wrong space.
References: https://ubuntu.com/security/CVE-2014-9322, https://marc.info/?l=oss-security&m=141866657032651&w=2, https://ubuntu.com/security/notices/USN-2464-1, https://ubuntu.com/security/notices/USN-2491-1, https://ubuntu.com/security/notices/USN-2443-1, https://ubuntu.com/security/notices/USN-2447-1, https://ubuntu.com/security/notices/USN-2446-1, https://ubuntu.com/security/notices/USN-2462-1, https://ubuntu.com/security/notices/USN-2448-1, https://ubuntu.com/security/notices/USN-2445-1, https://www.cve.org/CVERecord?id=CVE-2014-9322
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
