← Back to team overview

kernel-packages team mailing list archive

[Bug 1316735] Re: CVE-2014-1738

 

** Also affects: linux (Ubuntu Vivid)
   Importance: High
       Status: Fix Committed

** Also affects: linux-fsl-imx51 (Ubuntu Vivid)
   Importance: High
       Status: Invalid

** Also affects: linux-mvl-dove (Ubuntu Vivid)
   Importance: High
       Status: Invalid

** Also affects: linux-ec2 (Ubuntu Vivid)
   Importance: High
       Status: Invalid

** Also affects: linux-ti-omap4 (Ubuntu Vivid)
   Importance: High
       Status: Invalid

** Also affects: linux-lts-backport-maverick (Ubuntu Vivid)
   Importance: Undecided
       Status: New

** Also affects: linux-lts-backport-natty (Ubuntu Vivid)
   Importance: Undecided
       Status: New

** Also affects: linux-armadaxp (Ubuntu Vivid)
   Importance: High
       Status: Invalid

** Also affects: linux-lts-quantal (Ubuntu Vivid)
   Importance: High
       Status: Invalid

** Also affects: linux-lts-raring (Ubuntu Vivid)
   Importance: High
       Status: Invalid

** Also affects: linux-lts-saucy (Ubuntu Vivid)
   Importance: High
       Status: Invalid

-- 
You received this bug notification because you are a member of Kernel
Packages, which is subscribed to linux-armadaxp in Ubuntu.
https://bugs.launchpad.net/bugs/1316735

Title:
  CVE-2014-1738

Status in “linux” package in Ubuntu:
  Fix Committed
Status in “linux-armadaxp” package in Ubuntu:
  Invalid
Status in “linux-ec2” package in Ubuntu:
  Invalid
Status in “linux-fsl-imx51” package in Ubuntu:
  Invalid
Status in “linux-lts-backport-maverick” package in Ubuntu:
  New
Status in “linux-lts-backport-natty” package in Ubuntu:
  New
Status in “linux-lts-quantal” package in Ubuntu:
  Invalid
Status in “linux-lts-raring” package in Ubuntu:
  Invalid
Status in “linux-lts-saucy” package in Ubuntu:
  Invalid
Status in “linux-mvl-dove” package in Ubuntu:
  Invalid
Status in “linux-ti-omap4” package in Ubuntu:
  Invalid
Status in “linux” source package in Lucid:
  Fix Released
Status in “linux-armadaxp” source package in Lucid:
  Invalid
Status in “linux-ec2” source package in Lucid:
  Fix Released
Status in “linux-fsl-imx51” source package in Lucid:
  Invalid
Status in “linux-lts-backport-maverick” source package in Lucid:
  Won't Fix
Status in “linux-lts-backport-natty” source package in Lucid:
  Won't Fix
Status in “linux-lts-quantal” source package in Lucid:
  Invalid
Status in “linux-lts-raring” source package in Lucid:
  Invalid
Status in “linux-lts-saucy” source package in Lucid:
  Invalid
Status in “linux-mvl-dove” source package in Lucid:
  Invalid
Status in “linux-ti-omap4” source package in Lucid:
  Invalid
Status in “linux” source package in Precise:
  Fix Released
Status in “linux-armadaxp” source package in Precise:
  Fix Released
Status in “linux-ec2” source package in Precise:
  Invalid
Status in “linux-fsl-imx51” source package in Precise:
  Invalid
Status in “linux-lts-backport-maverick” source package in Precise:
  Won't Fix
Status in “linux-lts-backport-natty” source package in Precise:
  Won't Fix
Status in “linux-lts-quantal” source package in Precise:
  Fix Released
Status in “linux-lts-raring” source package in Precise:
  Fix Released
Status in “linux-lts-saucy” source package in Precise:
  Fix Released
Status in “linux-mvl-dove” source package in Precise:
  Invalid
Status in “linux-ti-omap4” source package in Precise:
  Fix Released
Status in “linux-lts-backport-maverick” source package in Quantal:
  Won't Fix
Status in “linux-lts-backport-natty” source package in Quantal:
  Won't Fix
Status in “linux-lts-backport-maverick” source package in Saucy:
  Won't Fix
Status in “linux-lts-backport-natty” source package in Saucy:
  Won't Fix
Status in “linux” source package in Trusty:
  Fix Released
Status in “linux-armadaxp” source package in Trusty:
  Invalid
Status in “linux-ec2” source package in Trusty:
  Invalid
Status in “linux-fsl-imx51” source package in Trusty:
  Invalid
Status in “linux-lts-backport-maverick” source package in Trusty:
  Won't Fix
Status in “linux-lts-backport-natty” source package in Trusty:
  Won't Fix
Status in “linux-lts-quantal” source package in Trusty:
  Invalid
Status in “linux-lts-raring” source package in Trusty:
  Invalid
Status in “linux-lts-saucy” source package in Trusty:
  Invalid
Status in “linux-mvl-dove” source package in Trusty:
  Invalid
Status in “linux-ti-omap4” source package in Trusty:
  Invalid
Status in “linux” source package in Utopic:
  Fix Committed
Status in “linux-armadaxp” source package in Utopic:
  Invalid
Status in “linux-ec2” source package in Utopic:
  Invalid
Status in “linux-fsl-imx51” source package in Utopic:
  Invalid
Status in “linux-lts-backport-maverick” source package in Utopic:
  Won't Fix
Status in “linux-lts-backport-natty” source package in Utopic:
  Won't Fix
Status in “linux-lts-quantal” source package in Utopic:
  Invalid
Status in “linux-lts-raring” source package in Utopic:
  Invalid
Status in “linux-lts-saucy” source package in Utopic:
  Invalid
Status in “linux-mvl-dove” source package in Utopic:
  Invalid
Status in “linux-ti-omap4” source package in Utopic:
  Invalid
Status in “linux” source package in Vivid:
  Fix Committed
Status in “linux-armadaxp” source package in Vivid:
  Invalid
Status in “linux-ec2” source package in Vivid:
  Invalid
Status in “linux-fsl-imx51” source package in Vivid:
  Invalid
Status in “linux-lts-backport-maverick” source package in Vivid:
  New
Status in “linux-lts-backport-natty” source package in Vivid:
  New
Status in “linux-lts-quantal” source package in Vivid:
  Invalid
Status in “linux-lts-raring” source package in Vivid:
  Invalid
Status in “linux-lts-saucy” source package in Vivid:
  Invalid
Status in “linux-mvl-dove” source package in Vivid:
  Invalid
Status in “linux-ti-omap4” source package in Vivid:
  Invalid

Bug description:
  The raw_cmd_copyout function in drivers/block/floppy.c in the Linux
  kernel through 3.14.3 does not properly restrict access to certain
  pointers during processing of an FDRAWCMD ioctl call, which allows
  local users to obtain sensitive information from kernel heap memory by
  leveraging write access to a /dev/fd device.

  Break-Fix: - 2145e15e0557a01b9195d1c7199a1b92cb9be81f

To manage notifications about this bug go to:
https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1316735/+subscriptions


References