Lucene search

K
veracodeVeracode Vulnerability DatabaseVERACODE:15670
HistoryMay 02, 2019 - 5:03 a.m.

Improper Access Control

2019-05-0205:03:25
Veracode Vulnerability Database
sca.analysiscenter.veracode.com
23

0.0004 Low

EPSS

Percentile

10.1%

A flaw was found in the way the Linux kernel’s floppy driver handled user space provided data in certain error code paths while processing FDRAWCMD IOCTL commands. A local user with write access to /dev/fdX could use this flaw to free (using the kfree() function) arbitrary kernel memory.

References