CVE-2014-8133
Description
arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mechanism, via a crafted application that makes a set_thread_area system call and later reads a 16-bit value.
Risk Information
Base Score
9.8
MODERATE
Vector
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.057
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Linux kernel (USN-2492-1) linux-image-3.2.0-76-generic_3.2.0-76.111_i386.deb | Linux |
| Linux kernel (USN-2492-1) linux-image-3.2.0-76-generic_3.2.0-76.111_amd64.deb | Linux |
| Linux kernel (USN-2492-1) linux-image-3.2.0-76-virtual_3.2.0-76.111_i386.deb | Linux |
| Linux kernel (USN-2492-1) linux-image-3.2.0-76-virtual_3.2.0-76.111_amd64.deb | Linux |
| Linux kernel (USN-2492-1) linux-image-3.2.0-76-generic-pae_3.2.0-76.111_i386.deb | Linux |
| Linux hardware enablement kernel from Trusty (USN-2515-1) linux-image-3.13.0-46-generic_3.13.0-46.79~precise1_i386.deb | Linux |
| Linux hardware enablement kernel from Trusty (USN-2515-1) linux-image-3.13.0-46-generic_3.13.0-46.79~precise1_amd64.deb | Linux |
| Linux kernel (USN-2516-1) linux-image-3.13.0-46-generic_3.13.0-46.79_i386.deb | Linux |
| Linux kernel (USN-2516-1) linux-image-3.13.0-46-generic_3.13.0-46.79_amd64.deb | Linux |
| Linux kernel (USN-2516-1) linux-image-3.13.0-46-lowlatency_3.13.0-46.79_i386.deb | Linux |
| Linux kernel (USN-2516-1) linux-image-3.13.0-46-lowlatency_3.13.0-46.79_amd64.deb | Linux |
| Linux hardware enablement kernel from Utopic (USN-2517-1) linux-image-3.16.0-31-generic_3.16.0-31.43~14.04.1_i386.deb | Linux |
| Linux hardware enablement kernel from Utopic (USN-2517-1) linux-image-3.16.0-31-generic_3.16.0-31.43~14.04.1_amd64.deb | Linux |
| Linux hardware enablement kernel from Utopic (USN-2517-1) linux-image-3.16.0-31-lowlatency_3.16.0-31.43~14.04.1_i386.deb | Linux |
| Linux hardware enablement kernel from Utopic (USN-2517-1) linux-image-3.16.0-31-lowlatency_3.16.0-31.43~14.04.1_amd64.deb | Linux |
| Dtrace-modules-3.8.13-68.el6uek update (ELSA-2015-3012) dtrace-modules-3.8.13-68.el6uek-0.4.3-4.el6.x86_64.rpm | Linux |
| Dtrace-modules-3.8.13-68.el7uek update (ELSA-2015-3012) dtrace-modules-3.8.13-68.el7uek-0.4.3-4.el7.x86_64.rpm | Linux |
| CVE-2014-8133 | NCM |
Patch Details
No records foundReferences
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234