Back

HIGH

kernel: lzo1x_decompress_safe() integer overflow

Published Jul 3, 2014

Description

Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Literal Run. NOTE: the author of the LZO algorithms says "the Linux kernel is *not* affected; media hype.

Affected products

Remediation

Red Hat statement

This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 5. Red Hat Enterprise Linux 7 and Red Hat Enterprise MRG 2 only support 64-bit architectures. Since exploiting this issue on 64-bit platforms is not feasible given the amount of input data that is necessary to trigger the integer overflow, we are currently not planning planning to fix this issue in Red Hat Enterprise Linux 7 and Red Hat Enterprise MRG 2.

Metrics

References (25)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Jul 3, 2014
Updated Jan 27, 2025
Reserved Jun 23, 2014
CISA Vulnrichment
Updated Apr 18, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Low
Public date Jun 26, 2014