VDB

CVE-2014-9585

CVE-2014-9585 PUBLISHED

The vdso_addr function in arch/x86/vdso/vma.c in the Linux kernel through 3.18.2 does not properly choose memory locations for the vDSO area, which makes it easier for local users to bypass the ASLR protection mechanism by guessing a location at the end of a PMD.

EPSS 0.04% · 14.1th percentile

Risk Scores

EPSS Score
0.04%
14.1th percentile

Affected Products

VendorProductVersions
Ubuntu:24.04:LTSlinux-gcp-6.110, *, *
Ubuntu:24.04:LTSlinux-lowlatency-hwe-6.116.11.0-1009.10~24.04.1, *, 6.11.0-1016.17~24.04.1
Ubuntu:24.04:LTSlinux-realtime6.8.1-1015.16, 0
Ubuntu:14.04:LTSlinux3.12.0-1.3, 3.12.0-2.5, 3.12.0-2.7
Ubuntu:18.04:LTSlinux-hwe5.3.0-40.32~18.04.1, 5.3.0-74.70, *
Ubuntu:Pro:20.04:LTSlinux-azure-fde-5.15*, 0, 5.15.0-1020.25~20.04.1.1
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:18.04:LTSlinux-hwe-edge0, *, *
Ubuntu:20.04:LTSlinux-riscv5.4.0-36.41, 5.4.0-28.32, 5.4.0-33.37
Ubuntu:22.04:LTSlinux-realtime5.15.0-1032.35, 0
Ubuntu:14.04:LTSlinux-lts-utopic3.16.0-30.40~14.04.1, 3.16.0-29.39~14.04.1, 3.16.0-28.38~14.04.1
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1076.79+cvm1.1, *, *
Ubuntu:22.04:LTSlinux-riscv5.15.0-1007.7, 5.15.0-1011.12, 5.15.0-1028.32
Ubuntu:24.04:LTSlinux-hwe-6.116.11.0-28.28~24.04.1, 6.11.0-25.25~24.04.1, 6.11.0-24.24~24.04.1
Ubuntu:18.04:LTSlinux-gcp4.15.0-1034.36, 0, 4.15.0-1001.1
Ubuntu:24.04:LTSlinux-azure-6.116.11.0-1018.18~24.04.1, 6.11.0-1017.17~24.04.1, 6.11.0-1015.15~24.04.1
Ubuntu:24.04:LTSlinux-riscv6.8.0-50.51.1, 6.8.0-52.53.1, 6.8.0-53.55.1
Ubuntu:24.04:LTSlinux-raspi-realtime6.8.0-2019.20, 0
Ubuntu:18.04:LTSlinux-azure4.18.0-1020.20~18.04.1, 4.15.0-1003.3, *
Ubuntu:20.04:LTSlinux-gke5.4.0-1055.58, 0, 5.4.0-1033.35

…and 2 more

Exploit Intelligence

Timeline

  • Jan 9, 2015 CVE Published
  • Feb 4, 2022 EPSS Score
  • Mar 29, 2022 EPSS Score
  • May 20, 2022 EPSS Score
  • Jul 12, 2022 EPSS Score
  • Sep 3, 2022 EPSS Score
  • Oct 26, 2022 EPSS Score
  • Dec 18, 2022 EPSS Score
  • Feb 8, 2023 EPSS Score
  • Mar 7, 2023 EPSS Score
  • Apr 2, 2023 EPSS Score
  • May 25, 2023 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›