CVE-2014-1738: Debian Linux
Low severity, CVSS 2.1. EPSS: 0.5% chance of exploitation in the next 30 days.
The raw_cmd_copyout function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly restrict access to certain pointers during processing of an FDRAWCMD ioctl call, which allows local users to obtain sensitive information from kernel heap memory by leveraging write access to a /dev/fd device.
Affected products
- Debian Debian Linux: version 6.0 only; version 7.0 only
- Linux Linux Kernel: up to and including 3.14.3
- Oracle Linux: version 5 only; version 6 only
- Red Hat Enterprise Linux Eus: version 5.6 only; version 6.3 only
- Suse Linux Enterprise Desktop: version 11 only
- Suse Linux Enterprise High Availability Extension: version 11 only
- Suse Linux Enterprise Real Time Extension: version 11 only
- Suse Linux Enterprise Server: version 11 only
Published 2014-05-11. Last modified 2026-06-17.