Linux Kernel 'compat_sys_recvmmsg()' Function Local Memory Corruption Vulnerability
BID:65255
Info
Linux Kernel 'compat_sys_recvmmsg()' Function Local Memory Corruption Vulnerability
| Bugtraq ID: | 65255 |
| Class: | Design Error |
| CVE: |
CVE-2014-0038 |
| Remote: | No |
| Local: | Yes |
| Published: | Jan 31 2014 12:00AM |
| Updated: | May 22 2014 01:03AM |
| Credit: | grsecurity |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
Linux Kernel 'compat_sys_recvmmsg()' Function Local Memory Corruption Vulnerability
The Linux Kernel is prone to a local memory-corruption vulnerability.
A local attacker can exploit this issue to execute arbitrary code with kernel privileges, corrupt the kernel memory, obtain sensitive information or crash the kernel, resulting in a denial-of-service condition.
Linux kernel 3.4 and above are vulnerable.
The Linux Kernel is prone to a local memory-corruption vulnerability.
A local attacker can exploit this issue to execute arbitrary code with kernel privileges, corrupt the kernel memory, obtain sensitive information or crash the kernel, resulting in a denial-of-service condition.
Linux kernel 3.4 and above are vulnerable.
Exploit / POC
Linux Kernel 'compat_sys_recvmmsg()' Function Local Memory Corruption Vulnerability
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
The following exploits are available:
Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product.
The following exploits are available:
Solution / Fix
Linux Kernel 'compat_sys_recvmmsg()' Function Local Memory Corruption Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Linux Kernel 'compat_sys_recvmmsg()' Function Local Memory Corruption Vulnerability
References:
References:
- Linux Homepage (Linux)