Back

MEDIUM

kernel: integer overflow and OOB read in drivers/block/floppy.c

Published Jul 26, 2019

Description

In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c does not validate the sect and head fields, as demonstrated by an integer overflow and out-of-bounds read. It can be triggered by an unprivileged local user when a floppy disk has been inserted. NOTE: QEMU creates the floppy device by default.

Affected products

Remediation

Red Hat mitigation

The kernel module named 'floppy' contains the affected code, this can be blacklisted using the standard blacklisting techniques or disabled in the systems BIOS. See https://access.redhat.com/solutions/41278 for how to blacklist a kernel module. Virtualized guest systems can also remove the system from the guests configuration to ensure that the module does not load.

References (27)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 26, 2019
Updated Aug 5, 2024
Reserved Jul 26, 2019
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Moderate
Public date Jul 26, 2019
ENISA EUVD
Assigner mitre
Published Jul 26, 2019
Updated Aug 5, 2024
Exploited since n/a
EUVD-2019-5511