4.7
CVSSv2

CVE-2014-6410

Published: 28/09/2014 Updated: 07/11/2023
CVSS v2 Base Score: 4.7 | Impact Score: 6.9 | Exploitability Score: 3.4
VMScore: 419
Vector: AV:L/AC:M/Au:N/C:N/I:N/A:C

Vulnerability Summary

The __udf_read_inode function in fs/udf/inode.c in the Linux kernel up to and including 3.16.3 does not restrict the amount of ICB indirection, which allows physically proximate malicious users to cause a denial of service (infinite loop or stack consumption) via a UDF filesystem with a crafted inode.

Vulnerable Product Search on Vulmon Subscribe to Product

linux linux kernel 3.16.0

linux linux kernel 3.16.2

linux linux kernel

linux linux kernel 3.16.1

Vendor Advisories

Synopsis Important: kernel security and bug fix update Type/Severity Security Advisory: Important Topic Updated kernel packages that fix multiple security issues and several bugsare now available for Red Hat Enterprise Linux 6Red Hat Product Security has rated this update as having Important securityimpact ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
Several security issues were fixed in the kernel ...
A stack overflow flaw caused by infinite recursion was found in the way the Linux kernel's Universal Disk Format (UDF) file system implementation processed indirect Information Control Blocks (ICBs) An attacker with physical access to the system could use a specially crafted UDF image to crash the system ...