Linux Kernel CVE-2014-4014 Local Privilege Escalation Vulnerability
BID:67988
Info
Linux Kernel CVE-2014-4014 Local Privilege Escalation Vulnerability
| Bugtraq ID: | 67988 |
| Class: | Design Error |
| CVE: |
CVE-2014-4014 |
| Remote: | No |
| Local: | Yes |
| Published: | Jun 10 2014 12:00AM |
| Updated: | Dec 20 2016 03:07AM |
| Credit: | Andy Lutomirski |
| Vulnerable: |
Ubuntu Ubuntu Linux 14.04 LTS Ubuntu Ubuntu Linux 13.10 Ubuntu Ubuntu Linux 12.04 LTS i386 Ubuntu Ubuntu Linux 12.04 LTS amd64 S.u.S.E. openSUSE 13.1 S.u.S.E. openSUSE 12.3 Oracle Linux 7 Oracle Linux 6 Oracle Enterprise Linux 7 Linux kernel 3.4.93 Linux kernel 3.2.60 Linux kernel 3.14.7 Linux kernel 3.12.22 Linux kernel 3.10.43 Linux kernel 2.6.32.62 IBM PowerKVM 2.1 Google Nexus Player 0 Google Nexus 6 |
| Not Vulnerable: | |
Discussion
Linux Kernel CVE-2014-4014 Local Privilege Escalation Vulnerability
The Linux kernel is prone to a local privilege-escalation vulnerability.
Local attackers may exploit this issue to gain elevated privileges or cause a kernel crash.
The Linux kernel is prone to a local privilege-escalation vulnerability.
Local attackers may exploit this issue to gain elevated privileges or cause a kernel crash.
Exploit / POC
Linux Kernel CVE-2014-4014 Local Privilege Escalation Vulnerability
The following exploit code is available:
The following exploit code is available:
Solution / Fix
Linux Kernel CVE-2014-4014 Local Privilege Escalation Vulnerability
Solution:
Updates are available. Please see the references or vendor advisory for more information.
Solution:
Updates are available. Please see the references or vendor advisory for more information.
References
Linux Kernel CVE-2014-4014 Local Privilege Escalation Vulnerability
References:
References:
- CVE-2014-4014: Linux kernel user namespace bug (seclists.org)
- fs,userns: Change inode_capable to capable_wrt_inode_uidgid (kernel.org)
- Linux Homepage (Linux)
- Linux kernel Homepage (kernel.org)
- Android Security Bulletin�??December 2016 (Google)
- openSUSE Security Update: kernel: security and bugfix update (SUSE)
- Security Bulletin: PowerKVM Kernel Vulnerabilities - Multiple CVEs (IBM)