|
|
Subscribe / Log in / New account

kernel: multiple vulnerabilities

Package(s):kernel CVE #(s):CVE-2014-7843 CVE-2014-7842 CVE-2014-7841 CVE-2014-7826 CVE-2014-7825
Created:November 21, 2014 Updated:March 3, 2015
Description:

From the Red Hat bug reports:

CVE-2014-7843 - It was found that a read of n*PAGE_SIZE+1 from /dev/zero will cause the kernel to panic due to an unhandled exception since it's not handling the single byte case with a fixup (anything larger than a single byte will properly fault.) A local, unprivileged user could use this flaw to crash the system.

CVE-2014-7842 - It was found that reporting emulation failures to user space can lead to either local or L2->L1 DoS. In the case of local DoS attacker needs access to MMIO area or be able to generate port access. Please note that on certain systems HPET is mapped to userspace as part of vdso (vvar) and thus an unprivileged user may generate MMIO transactions (and enter the emulator) this way.

CVE-2014-7841 - An SCTP server doing ASCONF will panic on malformed INIT ping-of-death in the form of:

     ------------ INIT[PARAM: SET_PRIMARY_IP] ------------>

A remote attacker could use this flaw to crash the system by sending a maliciously prepared SCTP packet in order to trigger a NULL pointer dereference on the server.

From the CVE entries:

CVE-2014-7826 - kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the ftrace subsystem, which allows local users to gain privileges or cause a denial of service (invalid pointer dereference) via a crafted application.

CVE-2014-7825 - kernel/trace/trace_syscalls.c in the Linux kernel through 3.17.2 does not properly handle private syscall numbers during use of the perf subsystem, which allows local users to cause a denial of service (out-of-bounds read and OOPS) or bypass the ASLR protection mechanism via a crafted application.

Alerts:
Oracle ELSA-2016-3502 kernel 2.6.39 2016-01-09
Oracle ELSA-2016-3502 kernel 2.6.39 2016-01-09
Scientific Linux SLSA-2016:0855-1 kernel 2016-06-16
Red Hat RHSA-2016:0855-01 kernel 2016-05-10
Scientific Linux SLSA-2015:2152-2 kernel 2015-12-21
Oracle ELSA-2015-2152 kernel 2015-11-25
Red Hat RHSA-2015:2152-02 kernel 2015-11-19
Scientific Linux SLSA-2015:0864-1 kernel 2015-04-21
Oracle ELSA-2015-0864 kernel 2015-04-21
CentOS CESA-2015:0864 kernel 2015-04-22
SUSE SUSE-SU-2015:0736-1 Real Time Linux Kernel 2015-04-20
Red Hat RHSA-2015:0864-01 kernel 2015-04-21
SUSE SUSE-SU-2015:0652-1 Linux kernel 2015-04-02
Scientific Linux SLSA-2015:0290-1 kernel 2015-03-25
SUSE SUSE-SU-2015:0581-1 kernel 2015-03-24
openSUSE openSUSE-SU-2015:0566-1 kernel 2015-03-21
Oracle ELSA-2015-3012 kernel 2015-03-19
Oracle ELSA-2015-3012 kernel 2015-03-19
SUSE SUSE-SU-2015:0529-1 the Linux Kernel 2015-03-18
Red Hat RHSA-2015:0695-01 kernel 2015-03-17
SUSE SUSE-SU-2015:0481-1 kernel 2015-03-11
Red Hat RHSA-2015:0290-01 kernel 2015-03-05
Oracle ELSA-2015-0290 kernel 2015-03-12
Red Hat RHSA-2015:0285-01 kernel 2015-03-03
Red Hat RHSA-2015:0284-01 kernel 2015-03-03
Oracle ELSA-2015-3005 kernel 2015-01-29
Oracle ELSA-2015-3005 kernel 2015-01-29
Oracle ELSA-2015-3004 kernel 2015-01-29
Oracle ELSA-2015-3004 kernel 2015-01-29
Oracle ELSA-2015-3003 kernel 2015-01-29
Oracle ELSA-2015-3003 kernel 2015-01-29
CentOS CESA-2015:0102 kernel 2015-01-30
CentOS CESA-2015:0102 kernel 2015-01-29
Scientific Linux SLSA-2015:0102-1 kernel 2015-01-28
Oracle ELSA-2015-0087 kernel 2015-01-28
Oracle ELSA-2015-0102 kernel 2015-01-28
CentOS CESA-2015:0087 kernel 2015-01-28
Red Hat RHSA-2015:0102-01 kernel 2015-01-28
Scientific Linux SLSA-2015:0087-1 kernel 2015-01-28
Red Hat RHSA-2015:0087-01 kernel 2015-01-27
Mandriva MDVSA-2015:027 kernel 2015-01-16
SUSE SUSE-SU-2015:0068-1 the Linux Kernel 2015-01-16
SUSE SUSE-SU-2014:1695-2 Linux kernel 2015-01-14
Ubuntu USN-2464-1 linux-ti-omap4 2015-01-13
Ubuntu USN-2467-1 linux-lts-utopic 2015-01-13
Ubuntu USN-2465-1 linux-lts-trusty 2015-01-13
Ubuntu USN-2463-1 kernel 2015-01-13
Ubuntu USN-2466-1 kernel 2015-01-13
Ubuntu USN-2468-1 kernel 2015-01-13
Fedora FEDORA-2014-17244 kernel 2015-01-05
SUSE SUSE-SU-2014:1695-1 kernel 2014-12-23
SUSE SUSE-SU-2014:1693-1 kernel 2014-12-23
SUSE SUSE-SU-2014:1693-2 kernel 2014-12-24
openSUSE openSUSE-SU-2014:1669-1 kernel 2014-12-19
openSUSE openSUSE-SU-2014:1677-1 kernel 2014-12-21
openSUSE openSUSE-SU-2014:1678-1 kernel 2014-12-21
Debian-LTS DLA-118-1 linux-2.6 2014-12-21
Ubuntu USN-2448-2 kernel 2014-12-19
Ubuntu USN-2447-2 kernel 2014-12-19
Ubuntu USN-2444-1 linux-ti-omap4 2014-12-11
Ubuntu USN-2447-1 linux-lts-utopic 2014-12-11
Ubuntu USN-2445-1 linux-lts-trusty 2014-12-11
Ubuntu USN-2448-1 kernel 2014-12-11
Ubuntu USN-2446-1 kernel 2014-12-11
Ubuntu USN-2443-1 kernel 2014-12-11
Ubuntu USN-2441-1 kernel 2014-12-11
Ubuntu USN-2442-1 EC2 kernel 2014-12-11
Debian DSA-3093-1 kernel 2014-12-08
Red Hat RHSA-2014:1943-01 kernel-rt 2014-12-02
Mandriva MDVSA-2014:230 kernel 2014-11-27
Fedora FEDORA-2014-15200 kernel 2014-11-20

to post comments


Copyright © 2025, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds