CVE-2014-1738
Summary
| CVE | CVE-2014-1738 |
|---|---|
| State | PUBLISHED |
| Assigner | Chrome |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2014-05-11 21:55:05 UTC |
| Updated | 2026-05-06 22:30:45 UTC |
| Description | The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device. |
Risk And Classification
CVSS v2.0 Breakdown
Access Vector
LocalAccess Complexity
LowAuthentication
NoneConfidentiality
PartialIntegrity
NoneAvailability
NoneAV:L/AC:L/Au:N/C:P/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Debian | Debian Linux | 6.0 | All | All | All |
| Operating System | Debian | Debian Linux | 7.0 | All | All | All |
| Operating System | Linux | Linux Kernel | All | All | All | All |
| Operating System | Oracle | Linux | 5 | - | All | All |
| Operating System | Oracle | Linux | 6 | - | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 5.6 | All | All | All |
| Operating System | Redhat | Enterprise Linux Eus | 6.3 | All | All | All |
| Operating System | Suse | Linux Enterprise Desktop | 11 | sp3 | All | All |
| Operating System | Suse | Linux Enterprise High Availability Extension | 11 | sp3 | All | All |
| Operating System | Suse | Linux Enterprise Real Time Extension | 11 | sp3 | All | All |
| Operating System | Suse | Linux Enterprise Server | 11 | sp3 | All | All |
| Operating System | Suse | Linux Enterprise Server | 11 | sp3 | All | All |
Vendor Declared Affected Products
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| linux.oracle.com | ELSA-2014-0771 - kernel security and bug fix update | af854a3a-2127-422b-91ae-364da2661108 | linux.oracle.com | |
| Debian -- Security Information -- DSA-2926-1 linux | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| Security Advisory SA59262 - Oracle Linux update for kernel - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| 1094299 – (CVE-2014-1737, CVE-2014-1738) CVE-2014-1737 CVE-2014-1738 kernel: block: floppy: privilege escalation via FDRAWCMD floppy ioctl command | af854a3a-2127-422b-91ae-364da2661108 | bugzilla.redhat.com | |
| [security-announce] SUSE-SU-2014:0683-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| [security-announce] SUSE-SU-2014:0667-1: important: Security update for | af854a3a-2127-422b-91ae-364da2661108 | lists.opensuse.org | |
| floppy: don't write kernel-only members to FDRAWCMD ioctl output · torvalds/linux@2145e15 · GitHub | af854a3a-2127-422b-91ae-364da2661108 | github.com | |
| Red Hat Customer Portal | af854a3a-2127-422b-91ae-364da2661108 | rhn.redhat.com | |
| oss-security - Linux kernel floppy ioctl kernel code execution | af854a3a-2127-422b-91ae-364da2661108 | www.openwall.com | |
| Security Advisory SA59599 - Ubuntu update for kernel - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Security Advisory SA59406 - Oracle Linux update for kernel-uek - Secunia | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| About Secunia Research | Flexera | af854a3a-2127-422b-91ae-364da2661108 | secunia.com | |
| Linux Kernel CVE-2014-1738 Local Privilege Escalation Vulnerability | af854a3a-2127-422b-91ae-364da2661108 | www.securityfocus.com | |
| Linux Kernel Floppy Driver Bugs Let Local Users Gain Elevated Privileges - SecurityTracker | af854a3a-2127-422b-91ae-364da2661108 | www.securitytracker.com | |
| linux.oracle.com | ELSA-2014-3043 | af854a3a-2127-422b-91ae-364da2661108 | linux.oracle.com | |
| Debian -- Security Information -- DSA-2928-1 linux-2.6 | af854a3a-2127-422b-91ae-364da2661108 | www.debian.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | af854a3a-2127-422b-91ae-364da2661108 | git.kernel.org | |
| kernel/git/torvalds/linux.git - Linux kernel source tree | MITRE | git.kernel.org | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.