<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T07:16:44.114835+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2014-00053</id>
    <title>bdu:2014-00053</title>
    <updated>2026-10-03T07:16:44.737080+00:00</updated>
    <content>bdu:2014-00053</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2014-00053"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/certfr-2014-avi-241</id>
    <title>certfr-2014-avi-241 — De multiples vulnérabilités ont été corrigées dans le noyau Linux
d'&lt;span class="textit"&gt;Ubuntu&lt;/span&gt;. Certaines d'ent…</title>
    <updated>2026-10-03T07:16:44.737159+00:00</updated>
    <content>certfr-2014-avi-241</content>
    <link href="https://cve.radiocsirt.org/vuln/certfr-2014-avi-241"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-97872</id>
    <title>EUVD-2026-97872</title>
    <updated>2026-10-03T07:16:44.737191+00:00</updated>
    <content>EUVD-2026-97872</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-97872"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2014-1737</id>
    <title>fkie_cve-2014-1737</title>
    <updated>2026-10-03T07:16:44.737218+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2014-1737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-vmrj-8qgc-5x6c</id>
    <title>GHSA-vmrj-8qgc-5x6c</title>
    <updated>2026-10-03T07:16:44.737262+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-vmrj-8qgc-5x6c"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2014-1737</id>
    <title>gsd-2014-1737</title>
    <updated>2026-10-03T07:16:44.737288+00:00</updated>
    <content>gsd-2014-1737</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2014-1737"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2014:0557</id>
    <title>RHSA-2014:0557 — Red Hat Security Advisory: kernel-rt security update</title>
    <updated>2026-10-03T07:16:44.737305+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: net: inet frag code race condition leading to user-after-free kernel: pty layer race condition leading to memory corruption kernel: block: floppy: privilege escalation via FDRAWCMD floppy ioctl command kernel: block: floppy: privilege escalation via FDRAWCMD floppy ioctl command kernel: ath9k: tid-&gt;sched race in ath_tx_aggr_sleep() kernel: net: rds: dereference of a NULL device in rds_iw_laddr_check() Kernel: net: mac80211: crash dues to AP powersave TX vs. wakeup race kernel: net: ping: refcount issue in ping_init_sock() function Kernel: mm: try_to_unmap_cluster() should lock_page() before mlocking</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2014:0557"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2014:0786</id>
    <title>RHSA-2014:0786 — Red Hat Security Advisory: kernel security, bug fix, and enhancement update</title>
    <updated>2026-10-03T07:16:44.737356+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>kernel: aio: insufficient sanitization of head in aio_read_events_ring() kernel: block: floppy: privilege escalation via FDRAWCMD floppy ioctl command kernel: block: floppy: privilege escalation via FDRAWCMD floppy ioctl command kernel: net: potential information leak when ubuf backed skbs are skb_zerocopy()ied kernel: net: ping: refcount issue in ping_init_sock() function Kernel: filter: prevent nla extensions to peek beyond the end of the message Kernel: filter: prevent nla extensions to peek beyond the end of the message kernel: futex: pi futexes requeue issue</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2014:0786"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/suse-ru-2015:0621-1</id>
    <title>SUSE-RU-2015:0621-1 — Security update for Linux kernel</title>
    <updated>2026-10-03T07:16:44.737403+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Security update for Linux kernel</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/suse-ru-2015:0621-1"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-1737</id>
    <title>UBUNTU-CVE-2014-1737</title>
    <updated>2026-10-03T07:16:44.737536+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> Ubuntu:14.04:LTS: linux</p>
<p>The raw_cmd_copyin function in drivers/block/floppy.c in the Linux kernel through 3.14.3 does not properly handle error conditions during processing of an FDRAWCMD ioctl call, which allows local users to trigger kfree operations and gain privileges by leveraging write access to a /dev/fd device. First, raw_cmd_ioctl calls raw_cmd_copyin. This function kmallocs space for a floppy_raw_cmd structure and stores the resulting allocation in the "rcmd" pointer argument. It then attempts to copy_from_user the structure from userspace. If this fails, an early EFAULT return is taken. The problem is that even if the early return is taken, the pointer to the non-/partially-initialized floppy_raw_cmd structure has already been returned via the "rcmd" pointer. Back out in raw_cmd_ioctl, it attempts to raw_cmd_free this pointer. raw_cmd_free attempts to free any DMA pages allocated for the raw command, kfrees the raw command structure itself, and follows the linked list, if any, of further raw commands (a user can specify the FD_RAW_MORE flag to signal that there are more raw commands to follow in a single FDRAWCMD ioctl). So, a malicious user can send a FDRAWCMD ioctl with a raw command argument structure that has some bytes inaccessible (ie. off the end of an allocated page). The copy_from_user will fail but raw_cmd_free will attempt to process the floppy_raw_cmd as if it had been fully initialized by the rest of raw_cmd_copyin. The user can control the arguments passed to fd_dma_mem_fre…</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ubuntu-cve-2014-1737"/>
  </entry>
</feed>
