PT-2019-3455 · Linux+3 · Linux Kernel+3
Denis Efremov
·
Published
2019-07-17
·
Updated
2021-05-28
·
CVE-2019-14284
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Linux kernel versions prior to 5.2.3
Description
The issue is related to a division-by-zero error in the
setup format params() function of the Linux kernel. This can be exploited to cause a denial of service. An unprivileged local user can trigger the bug by setting specific drive geometry values that result in F SECT PER TRACK being zero, followed by a floppy format operation. This can be done even without a floppy disk inserted, as QEMU creates the floppy device by default.Recommendations
For Linux kernel versions prior to 5.2.3, update to version 5.2.3 or later to resolve the issue.
As a temporary workaround, consider restricting access to the floppy device to minimize the risk of exploitation.
Fix
DoS
Divide By Zero
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Alt Linux
Linux Kernel
Suse
Ubuntu