CVE-2014-4699

Linux kernel <3.15.4 - Privilege Escalation

Title source: llm

Description

The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and fork system calls.

Exploits (2)

exploitdb WORKING POC
by Vitaly Nikolenko · clocallinux_x86-64
https://www.exploit-db.com/exploits/34134
nomisec WORKING POC 1 stars
by vnik5287 · poc
https://github.com/vnik5287/cve-2014-4699-ptrace

References (33)

... and 13 more

Scores

EPSS 0.0114
EPSS Percentile 78.5%

Details

CWE
CWE-362
Status published
Products (6)
canonical/ubuntu_linux 10.04
canonical/ubuntu_linux 12.04
canonical/ubuntu_linux 13.10
canonical/ubuntu_linux 14.04
debian/debian_linux 7.0
linux/linux_kernel 2.6.17 - 3.2.61
Published Jul 09, 2014
Tracked Since Feb 18, 2026