kernel: block: floppy: privilege escalation via FDRAWCMD floppy ioctl command
Published May 11, 2014
2.1
LOWCVSS 2.0
EPSS 0.51%
Description
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.
Affected products
No data.
Configuration 1
- ≤ 3.14.3
Configuration 2
- 5.6
- 6.3
Configuration 3
- 6.0
- 7.0
Configuration 5
- 11
- 11
- 11
- 11
- 11
No data.
Red Hat Enterprise Linux 5
kernel-0:2.6.18-371.9.1.el5
Fixed · RHSA-2014:0740
Red Hat Enterprise Linux 5.6 Long Life
kernel-0:2.6.18-238.53.1.el5
Fixed · RHSA-2014:0801
Red Hat Enterprise Linux 5.9 Extended Update Support
kernel-0:2.6.18-348.27.1.el5
Fixed · RHSA-2014:0772
Red Hat Enterprise Linux 6
kernel-0:2.6.32-431.20.3.el6
Fixed · RHSA-2014:0771
Red Hat Enterprise Linux 6.2 Advanced Update Support
kernel-0:2.6.32-220.52.1.el6
Fixed · RHSA-2014:0800
Red Hat Enterprise Linux 6.4 Extended Update Support
kernel-0:2.6.32-358.46.1.el6
Fixed · RHSA-2014:0900
Red Hat Enterprise Linux 7
kernel-0:3.10.0-123.4.2.el7
Fixed · RHSA-2014:0786
Red Hat Enterprise MRG 2
kernel-rt-0:3.10.33-rt32.34.el6rt
Fixed · RHSA-2014:0557
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 5 | kernel-0:2.6.18-371.9.1.el5 | Fixed | RHSA-2014:0740 |
| Red Hat Enterprise Linux 5.6 Long Life | kernel-0:2.6.18-238.53.1.el5 | Fixed | RHSA-2014:0801 |
| Red Hat Enterprise Linux 5.9 Extended Update Support | kernel-0:2.6.18-348.27.1.el5 | Fixed | RHSA-2014:0772 |
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-431.20.3.el6 | Fixed | RHSA-2014:0771 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | kernel-0:2.6.32-220.52.1.el6 | Fixed | RHSA-2014:0800 |
| Red Hat Enterprise Linux 6.4 Extended Update Support | kernel-0:2.6.32-358.46.1.el6 | Fixed | RHSA-2014:0900 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-123.4.2.el7 | Fixed | RHSA-2014:0786 |
| Red Hat Enterprise MRG 2 | kernel-rt-0:3.10.33-rt32.34.el6rt | Fixed | RHSA-2014:0557 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (21)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=2145e15e0557a01b9195d1c7199a1b92cb9be81f x_refsource_CONFIRM
- http://linux.oracle.com/errata/ELSA-2014-0771.html x_refsource_CONFIRM
- http://linux.oracle.com/errata/ELSA-2014-3043.html x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00007.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-05/msg00012.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2014-0800.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2014-0801.html vendor-advisoryx_refsource_REDHAT
- http://secunia.com/advisories/59262 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59309 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59406 third-party-advisoryx_refsource_SECUNIA
- http://secunia.com/advisories/59599 third-party-advisoryx_refsource_SECUNIA
- http://www.debian.org/security/2014/dsa-2926 vendor-advisoryx_refsource_DEBIAN
- http://www.debian.org/security/2014/dsa-2928 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2014/05/09/2 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/67302 vdb-entryx_refsource_BID
- http://www.securitytracker.com/id/1030474 vdb-entryx_refsource_SECTRACK
- https://access.redhat.com/security/cve/CVE-2014-1738 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1094299 x_refsource_CONFIRMIssue Tracking
- https://github.com/torvalds/linux/commit/2145e15e0557a01b9195d1c7199a1b92cb9be81f x_refsource_CONFIRM
- https://nvd.nist.gov/vuln/detail/CVE-2014-1738
- https://www.cve.org/CVERecord?id=CVE-2014-1738
Change history (0)
No recorded changes yet.