Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2014-9585

Опубликовано: 11 дек. 2014
Источник: redhat
CVSS2: 1.9
EPSS Низкий

Описание

The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.

An information leak flaw was found in the way the Linux kernel's Virtual Dynamic Shared Object (vDSO) implementation performed address randomization. A local, unprivileged user could use this flaw to leak kernel memory addresses to user-space.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 5kernelWill not fix
Red Hat Enterprise Linux 6kernelFixedRHSA-2015:108109.06.2015
Red Hat Enterprise Linux 7kernel-rtFixedRHSA-2015:178815.09.2015
Red Hat Enterprise Linux 7kernelFixedRHSA-2015:177815.09.2015
Red Hat Enterprise MRG 2kernel-rtFixedRHSA-2015:178715.09.2015

Показывать по

Дополнительная информация

Статус:

Low
https://bugzilla.redhat.com/show_bug.cgi?id=1181054kernel: ASLR bruteforce possible for vdso library

EPSS

Процентиль: 13%
0.00045
Низкий

1.9 Low

CVSS2

Связанные уязвимости

ubuntu
больше 10 лет назад

The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.

nvd
больше 10 лет назад

The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.

debian
больше 10 лет назад

The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel thro ...

github
около 3 лет назад

The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.

oracle-oval
около 10 лет назад

ELSA-2015-3043: Unbreakable Enterprise kernel security update (IMPORTANT)

EPSS

Процентиль: 13%
0.00045
Низкий

1.9 Low

CVSS2