Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-949p-32jv-ghmg

Опубликовано: 13 мая 2022
Источник: github
Github: Не прошло ревью

Описание

The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.

The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.

EPSS

Процентиль: 6%
0.00028
Низкий

Дефекты

CWE-200

Связанные уязвимости

ubuntu
около 11 лет назад

The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.

redhat
около 11 лет назад

The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.

nvd
около 11 лет назад

The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.

debian
около 11 лет назад

The raw_cmd_copyout function in drivers/block/floppy.c in the Linux ke ...

fstec
около 11 лет назад

Уязвимость операционной системы Linux, позволяющая злоумышленнику повысить свои привилегии

EPSS

Процентиль: 6%
0.00028
Низкий

Дефекты

CWE-200