CVE-2014-7826: Null Pointer Dereference
An out-of-bounds memory access flaw, CVE-2014-7825, was found in the syscall tracing functionality of the Linux kernel's perf subsystem. A local, unprivileged user could use this flaw to crash the system. Additionally, an out-of-bounds memory access flaw, CVE-2014-7826, was found in the syscall tracing functionality of the Linux kernel's ftrace subsystem. On a system with ftrace syscall tracing enabled, a local, unprivileged user could use this flaw to crash the system, or escalate their privileges.
Other sources
kernel/trace/tracesyscalls.c in the Linux kernel through 3.17.2 does ...
— Debian
Affected Software
Remediation
Patch Available
Patch Available
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-7826?
CVE-2014-7826 is considered a high severity vulnerability due to its potential to crash the system.
How do I fix CVE-2014-7826?
To fix CVE-2014-7826, ensure you update your Linux kernel to the latest patched version from your distribution.
Who is affected by CVE-2014-7826?
CVE-2014-7826 affects local unprivileged users on systems running vulnerable versions of the Linux kernel.
What types of systems are vulnerable to CVE-2014-7826?
Systems running specific versions of the Linux kernel, particularly those between 2.6.32 and 3.10.60, are vulnerable to CVE-2014-7826.
What is the impact of exploiting CVE-2014-7826?
Exploiting CVE-2014-7826 can lead to a denial of service by crashing the affected system.