kernel: isofs: unbound recursion when processing relocated directories
Published Sep 1, 2014
4.0
MEDIUMCVSS 2.0
EPSS 0.51%
Description
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry.
Affected products
No data.
- ≤ 3.16.1
- 3.16.0
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-504.3.3.el6
Fixed · RHSA-2014:1997
Red Hat Enterprise Linux 6.2 Advanced Update Support
kernel-0:2.6.32-220.60.2.el6
Fixed · RHSA-2015:0695
Red Hat Enterprise Linux 6.4 Advanced Update Support
kernel-0:2.6.32-358.59.1.el6
Fixed · RHSA-2015:0803
Red Hat Enterprise Linux 6.5 Extended Update Support
kernel-0:2.6.32-431.53.2.el6
Fixed · RHSA-2015:0782
Red Hat Enterprise Linux 7
kernel-0:3.10.0-123.20.1.el7
Fixed · RHSA-2015:0102
Red Hat Enterprise MRG 2
kernel-rt-0:3.10.33-rt32.51.el6rt
Fixed · RHSA-2014:1318
Red Hat Enterprise Linux 5
kernel
Will not fix
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-504.3.3.el6 | Fixed | RHSA-2014:1997 |
| Red Hat Enterprise Linux 6.2 Advanced Update Support | kernel-0:2.6.32-220.60.2.el6 | Fixed | RHSA-2015:0695 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | kernel-0:2.6.32-358.59.1.el6 | Fixed | RHSA-2015:0803 |
| Red Hat Enterprise Linux 6.5 Extended Update Support | kernel-0:2.6.32-431.53.2.el6 | Fixed | RHSA-2015:0782 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-123.20.1.el7 | Fixed | RHSA-2015:0102 |
| Red Hat Enterprise MRG 2 | kernel-rt-0:3.10.33-rt32.51.el6rt | Fixed | RHSA-2014:1318 |
| Red Hat Enterprise Linux 5 | kernel | Will not fix | n/a |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
References (28)
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=410dd3cf4c9b36f27ed4542ee18b1af5e68645a4 x_refsource_CONFIRM
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00006.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2014-10/msg00007.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2015-04/msg00020.html vendor-advisoryx_refsource_SUSE
- http://marc.info/?l=bugtraq&m=142722450701342&w=2 vendor-advisoryx_refsource_HP
- http://marc.info/?l=bugtraq&m=142722544401658&w=2 vendor-advisoryx_refsource_HP
- http://rhn.redhat.com/errata/RHSA-2014-1318.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0102.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0695.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0782.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2015-0803.html vendor-advisoryx_refsource_REDHAT
- http://www.openwall.com/lists/oss-security/2014/08/27/1 mailing-listx_refsource_MLIST
- http://www.securityfocus.com/bid/69428 vdb-entryx_refsource_BID
- http://www.ubuntu.com/usn/USN-2354-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2355-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2356-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2357-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2358-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-2359-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2014-5472 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1134099 x_refsource_CONFIRMIssue Tracking
- https://code.google.com/p/google-security-research/issues/detail?id=88 x_refsource_MISC
- https://exchange.xforce.ibmcloud.com/vulnerabilities/95556 vdb-entryx_refsource_XF
- https://github.com/torvalds/linux/commit/410dd3cf4c9b36f27ed4542ee18b1af5e68645a4 x_refsource_CONFIRMExploitPatch
- https://nvd.nist.gov/vuln/detail/CVE-2014-5472
- https://www.cve.org/CVERecord?id=CVE-2014-5472
Change history (0)
No recorded changes yet.