CVE-2014-8133: Linux Kernel
Low severity, CVSS 2.1. EPSS: 0.6% chance of exploitation in the next 30 days.
arch/x86/kernel/tls.c in the Thread Local Storage (TLS) implementation in the Linux kernel through 3.18.1 allows local users to bypass the espfix protection mechanism, and consequently makes it easier for local users to bypass the ASLR protection mechanism, via a crafted application that makes a set_thread_area system call and later reads a 16-bit value.
Affected products
- Linux Linux Kernel: up to and including 3.18.1; version 3.0 only; version 3.0.1 only; version 3.0.2 only; version 3.0.3 only; version 3.0.4 only; …
Published 2014-12-17. Last modified 2026-06-17.