VDB
CVE-2014-8133
CVE-2014-8133
PUBLISHED
arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mechanism, via a crafted application that makes a set_thread_area system call and later reads a 16-bit value.
EPSS 0.58% · 45.8th percentile
Risk Scores
EPSS Score
0.58%
45.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ubuntu:20.04:LTS | linux-gke | 5.4.0-1072.77, 5.4.0-1071.76, 5.4.0-1035.37 |
| Ubuntu:24.04:LTS | linux-realtime | 6.8.1-1015.16, 0 |
| Ubuntu:18.04:LTS | linux-gcp | 4.15.0-1009.9, 4.15.0-1023.24, * |
| Ubuntu:24.04:LTS | linux-lowlatency-hwe-6.11 | *, 6.11.0-1016.17~24.04.1, 6.11.0-1014.15~24.04.1 |
| Ubuntu:24.04:LTS | linux-riscv | 6.8.0-53.55.1, 6.8.0-52.53.1, 6.8.0-58.60.1 |
| Ubuntu:20.04:LTS | linux-riscv | 5.4.0-36.41, 5.4.0-30.34, 5.4.0-24.28 |
| Ubuntu:22.04:LTS | linux-riscv | 5.15.0-1015.17, 0, 5.13.0-1004.4 |
| Ubuntu:Pro:20.04:LTS | linux-azure-fde-5.15 | 5.15.0-1035.42~20.04.1.1, 5.15.0-1036.43~20.04.1.1, 5.15.0-1034.41~20.04.1.2 |
| Ubuntu:18.04:LTS | linux-azure | 4.15.0-1012.12, 5.0.0-1020.21~18.04.1, 5.0.0-1016.17~18.04.1 |
| Ubuntu:22.04:LTS | linux-realtime | 0, 5.15.0-1032.35 |
| Ubuntu:18.04:LTS | linux-hwe-edge | 5.0.0-20.21~18.04.1, 5.0.0-19.20~18.04.1, 5.0.0-17.18~18.04.1 |
| Ubuntu:24.04:LTS | linux-hwe-6.11 | 6.11.0-26.26~24.04.1, 0, * |
| Ubuntu:20.04:LTS | linux-azure-fde | 5.4.0-1065.68+cvm2.1, 5.4.0-1080.83+cvm1.1, 0 |
| Ubuntu:20.04:LTS | linux-gkeop | 5.4.0-1067.71, 0, 5.4.0-1008.9 |
| Ubuntu:14.04:LTS | linux-lts-utopic | 3.16.0-28.38~14.04.1, 0, 3.16.0-29.39~14.04.1 |
| Ubuntu:14.04:LTS | linux | 3.12.0-2.5, 3.12.0-2.7, 3.13.0-7.25 |
| Ubuntu:24.04:LTS | linux-raspi-realtime | 6.8.0-2019.20, 0 |
| Ubuntu:20.04:LTS | linux-raspi2 | 0, 5.3.0-1014.16, 5.4.0-1006.6 |
| Ubuntu:24.04:LTS | linux-gcp-6.11 | *, 6.11.0-1017.17~24.04.1, 6.11.0-1016.16~24.04.1 |
| Ubuntu:18.04:LTS | linux-hwe | 4.18.0-22.23~18.04.1, 4.18.0-24.25~18.04.1, 4.18.0-25.26~18.04.1 |
…and 2 more
Timeline
- Apr 24, 2012 CVE Published
- Feb 4, 2022 EPSS Score
- Mar 29, 2022 EPSS Score
- May 21, 2022 EPSS Score
- Jul 15, 2022 EPSS Score
- Sep 6, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 21, 2022 EPSS Score
- Feb 13, 2023 EPSS Score
- Apr 7, 2023 EPSS Score
- May 30, 2023 EPSS Score
- Jul 22, 2023 EPSS Score
References
- https://ubuntu.com/security/CVE-2014-8133 third-party-advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/arch/x86?id=41bdc78544b8a93a9c6814b8bbbfef966272abbe third-party-advisory
- https://marc.info/?l=oss-security&m=141866657032651&w=2 third-party-advisory
- https://ubuntu.com/security/notices/USN-2490-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-2491-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-2492-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-2493-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-2515-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-2516-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-2517-1 vendor-advisory
- https://ubuntu.com/security/notices/USN-2518-1 vendor-advisory
- https://www.cve.org/CVERecord?id=CVE-2014-8133 third-party-advisory