CVE-2014-4699: Canonical Ubuntu Linux
Medium severity, CVSS 6.9. EPSS: 2.3% chance of exploitation in the next 30 days.
The Linux kernel before 3.15.4 on Intel processors does not properly restrict use of a non-canonical value for the saved RIP address in the case of a system call that does not use IRET, which allows local users to leverage a race condition and gain privileges, or cause a denial of service (double fault), via a crafted application that makes ptrace and fork system calls.
Affected products
- Canonical Ubuntu Linux: version 10.04 only; version 12.04 only; version 13.10 only; version 14.04 only
- Debian Debian Linux: version 7.0 only
- Linux Linux Kernel: from 2.6.17, before 3.2.61 (fixed in 3.2.61); from 3.3, before 3.4.97 (fixed in 3.4.97); from 3.5, before 3.10.47 (fixed in 3.10.47); from 3.11, before 3.12.25 (fixed in 3.12.25); from 3.13, before 3.14.11 (fixed in 3.14.11); from 3.15, before 3.15.4 (fixed in 3.15.4)
Published 2014-07-09. Last modified 2026-06-17.