kernel: integer overflow and OOB read in drivers/block/floppy.c
Published Jul 26, 2019
6.8
MEDIUMCVSS 3.0
EPSS 0.73%
Description
In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c does not validate the sect and head fields, as demonstrated by an integer overflow and out-of-bounds read. It can be triggered by an unprivileged local user when a floppy disk has been inserted. NOTE: QEMU creates the floppy device by default.
Affected products
No data.
- < 5.2.3
No data.
Red Hat Enterprise Linux 7
kernel-0:3.10.0-1127.el7
Fixed · RHSA-2020:1016
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-1127.rt56.1093.el7
Fixed · RHSA-2020:1070
Red Hat Enterprise Linux 7.7 Extended Update Support
kernel-0:3.10.0-1062.26.1.el7
Fixed · RHSA-2020:2522
Red Hat Enterprise Linux 5
kernel
Out of support scope
Red Hat Enterprise Linux 6
kernel
Not affected
Red Hat Enterprise Linux 7
kernel-alt
Will not fix
Red Hat Enterprise Linux 8
kernel
Not affected
Red Hat Enterprise Linux 8
kernel-rt
Not affected
Red Hat Enterprise MRG 2
kernel-rt
Out of support scope
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-1127.el7 | Fixed | RHSA-2020:1016 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-1127.rt56.1093.el7 | Fixed | RHSA-2020:1070 |
| Red Hat Enterprise Linux 7.7 Extended Update Support | kernel-0:3.10.0-1062.26.1.el7 | Fixed | RHSA-2020:2522 |
| Red Hat Enterprise Linux 5 | kernel | Out of support scope | n/a |
| Red Hat Enterprise Linux 6 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 7 | kernel-alt | Will not fix | n/a |
| Red Hat Enterprise Linux 8 | kernel | Not affected | n/a |
| Red Hat Enterprise Linux 8 | kernel-rt | Not affected | n/a |
| Red Hat Enterprise MRG 2 | kernel-rt | Out of support scope | n/a |
No package ranges for this CVE.
Remediation
Red Hat mitigation
The kernel module named 'floppy' contains the affected code, this can be blacklisted using the standard blacklisting techniques or disabled in the systems BIOS. See https://access.redhat.com/solutions/41278 for how to blacklist a kernel module. Virtualized guest systems can also remove the system from the guests configuration to ensure that the module does not load.
References (27)
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00055.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2019-08/msg00056.html vendor-advisoryx_refsource_SUSE
- http://packetstormsecurity.com/files/154059/Slackware-Security-Advisory-Slackware-14.2-kernel-Updates.html x_refsource_MISC
- http://packetstormsecurity.com/files/154408/Kernel-Live-Patch-Security-Notice-LSN-0055-1.html x_refsource_MISC
- http://packetstormsecurity.com/files/154951/Kernel-Live-Patch-Security-Notice-LSN-0058-1.html x_refsource_MISC
- https://access.redhat.com/security/cve/CVE-2019-14283 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1734243 Issue Tracking
- https://cdn.kernel.org/pub/linux/kernel/v5.x/ChangeLog-5.2.3 x_refsource_MISCRelease NotesVendor Advisory
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2019-5511 Advisory
- https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=da99466ac243f15fbba65bd261bfc75ffa1532b6 x_refsource_MISCPatchVendor Advisory
- https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=da99466ac243f15fbba65bd261bfc75ffa1532b6
- https://github.com/torvalds/linux/commit/da99466ac243f15fbba65bd261bfc75ffa1532b6 x_refsource_MISCPatchThird Party Advisory
- https://lists.debian.org/debian-lts-announce/2019/08/msg00016.html mailing-listx_refsource_MLIST
- https://lists.debian.org/debian-lts-announce/2019/08/msg00017.html mailing-listx_refsource_MLIST
- https://nvd.nist.gov/vuln/detail/CVE-2019-14283
- https://seclists.org/bugtraq/2019/Aug/13 mailing-listx_refsource_BUGTRAQ
- https://seclists.org/bugtraq/2019/Aug/18 mailing-listx_refsource_BUGTRAQ
- https://seclists.org/bugtraq/2019/Aug/26 mailing-listx_refsource_BUGTRAQ
- https://security.netapp.com/advisory/ntap-20190905-0002/ x_refsource_CONFIRM
- https://usn.ubuntu.com/4114-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4115-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4116-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4117-1/ vendor-advisoryx_refsource_UBUNTU
- https://usn.ubuntu.com/4118-1/ vendor-advisoryx_refsource_UBUNTU
- https://www.cve.org/CVERecord?id=CVE-2019-14283
- https://www.debian.org/security/2019/dsa-4495 vendor-advisoryx_refsource_DEBIAN
- https://www.debian.org/security/2019/dsa-4497 vendor-advisoryx_refsource_DEBIAN
Change history (0)
No recorded changes yet.