Red Hat Bugzilla – Bug 1109774
CVE-2014-1739 Kernel: drivers: media: an information leakage
Last modified: 2015-08-21 19:52:46 EDT
Linux kernel built with the Multimedia support(CONFIG_MEDIA_SUPPORT) to enable
web-cam, video grabber devices, is vulnerable to an information leakage flaw.
It could occur while doing an ioctl(2) call on a media device file.
A user/process able to access the /dev/media0 device file could use this flaw
to leak kernel memory bytes.
This issue does not affect the versions of Linux kernel as shipped with Red Hat Enterprise Linux 5, Red Hat Enterprise Linux 6 and Red Hat Enterprise MRG 2.
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1109778]
An information leak flaw was found in the way the Linux kernel handled media device enumerate entities IOCTL requests. A local user able to access the /dev/media0 device file could use this flaw to leak kernel memory bytes.
This issue has been addressed in the following products:
Red Hat Enterprise Linux 7
Via RHSA-2014:1971 https://rhn.redhat.com/errata/RHSA-2014-1971.html