CVE-2014-8133
Published: 17 December 2014
arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mechanism, via a crafted application that makes a set_thread_area system call and later reads a 16-bit value.
From the Ubuntu security team
Andy Lutomirski discovered an information leak in the Linux kernel's Thread Local Storage (TLS) implementation allowing users to bypass the espfix to obtain information that could be used to bypass the Address Space Layout Randomization (ASLR) protection mechanism. A local user could exploit this flaw to obtain potentially sensitive information from kernel memory.
Notes
Author | Note |
---|---|
jdstrand | android kernels (flo, goldfish, grouper, maguro, mako and manta) are not supported on the Ubuntu Touch 14.04 preview kernels linux-lts-saucy no longer receives official support linux-lts-quantal no longer receives official support |
Status
Package | Release | Status |
---|---|---|
linux Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
Patches: Introduced by 1da177e4c3f41524e886b7f1b8a0c1fc7321cac2 |
||
linux-2.6 Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-armadaxp Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
This package is not directly supported by the Ubuntu Security Team | ||
linux-aws Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-ec2 Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-flo Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-fsl-imx51 Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-gke Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-goldfish Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-grouper Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-hwe Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-hwe-edge Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-linaro-omap Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-linaro-shared Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-linaro-vexpress Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-lts-quantal Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
This package is not directly supported by the Ubuntu Security Team | ||
linux-lts-raring Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-lts-saucy Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
This package is not directly supported by the Ubuntu Security Team | ||
linux-lts-trusty Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-lts-utopic Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-lts-vivid Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-lts-wily Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-lts-xenial Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-maguro Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-mako Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-manta Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-mvl-dove Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-qcm-msm Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-raspi2 Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-snapdragon Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
linux-ti-omap4 Launchpad, Ubuntu, Debian |
upstream |
Released
(3.19~rc1)
|
References
- https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-8133
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/arch/x86?id=41bdc78544b8a93a9c6814b8bbbfef966272abbe
- https://marc.info/?l=oss-security&m=141866657032651&w=2
- https://ubuntu.com/security/notices/USN-2490-1
- https://ubuntu.com/security/notices/USN-2491-1
- https://ubuntu.com/security/notices/USN-2492-1
- https://ubuntu.com/security/notices/USN-2493-1
- https://ubuntu.com/security/notices/USN-2515-1
- https://ubuntu.com/security/notices/USN-2516-1
- https://ubuntu.com/security/notices/USN-2517-1
- https://ubuntu.com/security/notices/USN-2518-1
- NVD
- Launchpad
- Debian