Kernel Heap Memory Disclosure Vulnerability in Linux Kernel through 3.14.3

Kernel Heap Memory Disclosure Vulnerability in Linux Kernel through 3.14.3

CVE-2014-1738 · LOW Severity

AV:L/AC:L/AU:N/C:P/I:N/A:N

The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.

Learn more about our Cis Benchmark Audit For Distribution Independent Linux.