CVE-2014-1738, CVE-2014-1737
Issue
- This issue is caused due to an error in raw_cmd_copyout function of drivers/block/floppy.c in the Linux kernel while handling FDRAWCMD ioctl command.
- A local attacker with write access to /dev/fdX could use this issue to obtain sensitive information from kernel heap memory.
Environment
- Red Hat Enterprise Linux (RHEL) 6
- Red Hat Enterprise Linux (RHEL) 5
- Red Hat Enterprise MRG 2
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.