The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.
References
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: Chrome
Published: 2014-05-11T21:00:00
Updated: 2017-12-20T19:57:01
Reserved: 2014-01-29T00:00:00
Link: CVE-2014-1737
JSON object: View
NVD Information
Status : Modified
Published: 2014-05-11T21:55:05.810
Modified: 2023-11-07T02:19:17.597
Link: CVE-2014-1737
JSON object: View
Redhat Information
No data.
CWE