Linux Kernel 'vdso _ addr () 'Function Local Security Restriction Bypass Vulnerability
Release date:
Updated on:
Affected Systems:
Linux kernel <3.18.2
Description:
Bugtraq id: 71990
CVE (CAN) ID: CVE-2014-9585
Linux Kernel is the Kernel of the Linux operating system.
In versions earlier than Linux kernel 3.18.2, arch/x86/vdso/vma. the vdso_addr function in c does not correctly select the memory location of the vDSO region. This allows local users to guess the last position of the PMD and bypass the ASLR protection mechanism.
<* Source: Reno Robert
*>
Suggestion:
Vendor patch:
Linux
-----
The vendor has released a patch to fix this security problem. Please download it from the vendor's homepage:
Http://git.kernel.org /? P = linux/kernel/git/tip. git; a = commit; h = fbe1bf140671619508dfa575d74a185ae53c5dbb
The Ubuntu 13.10 (Saucy Salamander) Kernel has been upgraded to Linux Kernel 3.10 RC5
Linux Kernel 3.4.62 LTS is now available for download
How to install Linux kernel 13.10 On Ubuntu 3.12
How to install the 3.16.7 CKT2 kernel in Ubuntu 14.10, Ubuntu 14.04, and its derivative versions
Linux Kernel: click here
Linux Kernel: click here
This article permanently updates the link address: