CVE-2014-3534: High severity linux kernel vulnerability
arch/s390/kernel/ptrace.c in the Linux kernel before 3.15.8 on the s390 platform does not properly restrict address-space control operations in PTRACEPOKEUSRAREA requests, which allows local users to obtain read and write access to kernel memory locations, and consequently gain privileges, via a crafted application that makes a ptrace system call.
Other sources
It was found that Linux kernel's ptrace subsystem did not properly sanitize psw mask value. On s390 systems, an unprivileged local user could use this flaw to set address space control bits to kernel space combination and thus gain read/write access to kernel memory.
— Red Hat
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-3534?
CVE-2014-3534 is classified as a high severity vulnerability due to its potential to allow local users to escalate privileges by manipulating kernel memory.
How do I fix CVE-2014-3534?
To fix CVE-2014-3534, update the Linux kernel to version 3.15.8 or later, where this vulnerability has been addressed.
What platforms are affected by CVE-2014-3534?
CVE-2014-3534 affects the s390 platform of the Linux kernel, specifically versions prior to 3.15.8.
What type of vulnerability is CVE-2014-3534?
CVE-2014-3534 is a local privilege escalation vulnerability that allows users to read and write kernel memory.
Is CVE-2014-3534 specific to any Linux distributions?
While CVE-2014-3534 primarily affects the Linux kernel, it may also impact specific distributions like Debian if running affected kernel versions.