CVE-2014-4699
MEDIUM 6.9EPSS 2.3%
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and fork system calls.
- CVSS v2.0
- 6.9 MEDIUM
AV:L/AC:M/Au:N/C:C/I:C/A:C - EPSS
- 2.32% chance of exploitation in the next 30 days, 82th percentile
- Published
- 2014-07-09
- Updated
- 2024-08-06
Proof-of-concept exploits (3)
- http://packetstormsecurity.com/files/127573/Linux-Kernel-ptrace-sysret-Local-Privilege-Es…
- http://www.exploit-db.com/exploits/34134
- vnik5287/cve-2014-4699-ptrace1★ · 2019-07-23