CVE-2014-1737
Summary
| CVE | CVE-2014-1737 |
|---|---|
| State | PUBLISHED |
| Assigner | Chrome |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-05-11 21:55:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
CompleteIntegrity
CompleteAvailability
CompleteAV:L/AC:L/Au:N/C:C/I:C/A:C
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Linux | Linux Kernel | All | All | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| linux.oracle.com | ELSA-2014-0771 - kernel security and bug fix update | af854a3a-2127-422b-91ae-364da2661108 | linux.oracle.com | |
| Linux Kernel CVE-2014-1737 Function Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Debian -- Security Information -- DSA-2926-1 linux | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Security Advisory SA59262 - Oracle Linux update for kernel - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 1094299 – (CVE-2014-1737, CVE-2014-1738) CVE-2014-1737 CVE-2014-1738 kernel: block: floppy: privilege escalation via FDRAWCMD floppy ioctl command | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| [security-announce] SUSE-SU-2014:0683-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [security-announce] SUSE-SU-2014:0667-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| floppy: ignore kernel-only members in FDRAWCMD ioctl input · torvalds/linux@ef87dbe · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| oss-security - Linux kernel floppy ioctl kernel code execution | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Security Advisory SA59599 - Ubuntu update for kernel - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA59406 - Oracle Linux update for kernel-uek - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Linux Kernel Floppy Driver Bugs Let Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| linux.oracle.com | ELSA-2014-3043 | af854a3a-2127-422b-91ae-364da2661108 | linux.oracle.com | |
| Debian -- Security Information -- DSA-2928-1 linux-2.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.