CVE-2014-1737: Debian Linux
High severity, CVSS 7.2. EPSS: 0.5% chance of exploitation in the next 30 days.
The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.
Affected products
- Debian Debian Linux: version 6.0 only; version 7.0 only
- Linux Linux Kernel: before 3.2.59 (fixed in 3.2.59); from 3.3, before 3.4.90 (fixed in 3.4.90); from 3.5, before 3.10.40 (fixed in 3.10.40); from 3.11, before 3.12.20 (fixed in 3.12.20); from 3.13, before 3.14.4 (fixed in 3.14.4)
- Oracle Linux: version 5 only; version 6 only
- Red Hat Enterprise Linux Eus: version 5.6 only; version 6.3 only
- Suse Linux Enterprise Desktop: version 11 only
- Suse Linux Enterprise High Availability Extension: version 11 only
- Suse Linux Enterprise Real Time Extension: version 11 only
- Suse Linux Enterprise Server: version 11 only
Published 2014-05-11. Last modified 2026-06-17.