Back to search
CVE-2014-3534
Published: Aug 1, 2014
Modified: Aug 6, 2024
PUBLISHED
Description
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACE_POKEUSR_AREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a crafted application that makes a ptrace system call.
| Vendor | Product | Versions |
|---|---|---|
n/a | n/a | affected n/a |
References
linux-cve20143534-priv-esc(95069)
vdb-entry
x_refsource_XF
https://bugzilla.redhat.com/show_bug.cgi?id=1114089
x_refsource_CONFIRM
59790
third-party-advisory
x_refsource_SECUNIA
http://www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.15.8
x_refsource_CONFIRM
68940
vdb-entry
x_refsource_BID
1030683
vdb-entry
x_refsource_SECTRACK
109546
vdb-entry
x_refsource_OSVDB
DSA-2992
vendor-advisory
x_refsource_DEBIAN
60351
third-party-advisory
x_refsource_SECUNIA
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now