We have moved to a new Sailfish OS Forum. Please start new discussions there.

Revision history [back]

click to hide/show revision 1
initial version

posted 2017-07-27 13:01:32 +0200

Preserve the user r/w register TPIDRURW on context switch and fork in kernel-arch-arm CVE-2014-9870 remote

The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, aka Android internal bug 28749743 and Qualcomm internal bug CR561044. CVSS v3 Base Score: 7.8high (attack range: remote)

Patch is available

files affected: kernel-adaptation-sbj-3.4.108.20161101.1/arch/arm/include/asm/ thread_info.h, tls.h
kernel-adaptation-sbj-3.4.108.20161101.1/arch/arm/kernel/ entry-armv.S, process.c, ptrace.c, traps.c

Preserve the user r/w register TPIDRURW on context switch and fork in kernel-arch-arm CVE-2014-9870 remote

The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, aka Android internal bug 28749743 and Qualcomm internal bug CR561044. CVSS v3 Base Score: 7.8high (attack range: remote)

Patch is available

files affected: kernel-adaptation-sbj-3.4.108.20161101.1/arch/arm/include/asm/ thread_info.h, tls.h
......... kernel-adaptation-sbj-3.4.108.20161101.1/arch/arm/kernel/ entry-armv.S, process.c, ptrace.c, traps.c

Preserve the user r/w register TPIDRURW on context switch and fork in kernel-arch-arm CVE-2014-9870 remote

The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, aka Android internal bug 28749743 and Qualcomm internal bug CR561044. CVSS v3 Base Score: 7.8high (attack range: remote)

Patch is available

files affected: kernel-adaptation-sbj-3.4.108.20161101.1/arch/arm/include/asm/ thread_info.h, tls.h
......... kernel-adaptation-sbj-3.4.108.20161101.1/arch/arm/kernel/ entry-armv.S, process.c, ptrace.c, traps.c

Preserve the user r/w register TPIDRURW on context switch and fork in kernel-arch-arm CVE-2014-9870 remote

The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, aka Android internal bug 28749743 and Qualcomm internal bug CR561044. CVSS v3 Base Score: 7.8high (attack range: remote)

Patch is availableavailable.

files affected: kernel-adaptation-sbj-3.4.108.20161101.1/arch/arm/include/asm/ thread_info.h, tls.h
kernel-adaptation-sbj-3.4.108.20161101.1/arch/arm/kernel/ entry-armv.S, process.c, ptrace.c, traps.c

Preserve the user r/w register TPIDRURW on context switch and fork in kernel-arch-arm CVE-2014-9870 remote

The Linux kernel before 3.11 on ARM platforms, as used in Android before 2016-08-05, does not properly consider user-space access to the TPIDRURW register, which allows local users to gain privileges via a crafted application, aka Android internal bug 28749743 and Qualcomm internal bug CR561044. CVSS v3 Base Score: 7.8high (attack range: remote)

Patch is available.available

files affected: kernel-adaptation-sbj-3.4.108.20161101.1/arch/arm/include/asm/ thread_info.h, tls.h
kernel-adaptation-sbj-3.4.108.20161101.1/arch/arm/kernel/ entry-armv.S, process.c, ptrace.c, traps.c