UBUNTU-CVE-2019-14283
Dashboard / Vulnerabilities / UBUNTU-CVE-2019-14283
UBUNTU-CVE-2019-14283
Summary:
Details: In the Linux kernel before 5.2.3, set_geometry in drivers/block/floppy.c does not validate the sect and head fields, as demonstrated by an integer overflow and out-of-bounds read. It can be triggered by an unprivileged local user when a floppy disk has been inserted. NOTE: QEMU creates the floppy device by default.
References: https://ubuntu.com/security/CVE-2019-14283, https://git.kernel.org/linus/da99466ac243f15fbba65bd261bfc75ffa1532b6, https://ubuntu.com/security/notices/USN-4114-1, https://ubuntu.com/security/notices/USN-4115-1, https://ubuntu.com/security/notices/USN-4116-1, https://ubuntu.com/security/notices/USN-4117-1, https://ubuntu.com/security/notices/USN-4118-1, https://www.cve.org/CVERecord?id=CVE-2019-14283
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/linux-aws?arch=source&distro=trusty%2Fesm
Affected ranges
Type: ECOSYSTEM
Events:
