Severity
5.0MEDIUMNVD
EPSS
10.1%
top 6.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 3
Latest updateMay 13

Description

Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run that would be improperly handled by programs not complying with an API limitation, a different vulnerability than CVE-2014-4715.

CVSS vector

AV:N/AC:L/C:N/I:N/A:PExploitability: 10.0 | Impact: 2.9

Affected Packages3 packages

NVDlinux/linux_kernel< 3.15.2
Debianlinux/linux_kernel< 3.14.9-1+3
Debianlz4_project/lz4< 0.0~r119-1+3

🔴Vulnerability Details

3
GHSA
GHSA-c7c4-fwj7-36pr: Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompr2022-05-13
CVEList
CVE-2014-4611: Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompr2014-07-03
OSV
CVE-2014-4611: Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompr2014-07-03

📋Vendor Advisories

7
Ubuntu
Linux kernel vulnerabilities2014-07-17
Ubuntu
Linux kernel vulnerabilities2014-07-17
Ubuntu
Linux kernel (Trusty HWE) vulnerabilities2014-07-17
Ubuntu
Linux kernel (Saucy HWE) vulnerabilities2014-07-17
Red Hat
lz4: LZ4_decompress_generic() integer overflow (32-bit arches)2014-07-03

💬Community

5
HackerOne
LZ4 Core2014-07-25
Bugzilla
CVE-2014-4611 LZ4: LZ4_decompress_generic() integer overflow [fedora-all]2014-06-27
Bugzilla
CVE-2014-4611 kernel: LZ4: LZ4_decompress_generic() integer overflow [fedora-all]2014-06-27
Bugzilla
CVE-2014-4611 LZ4: LZ4_decompress_generic() integer overflow [epel-all]2014-06-27
Bugzilla
CVE-2014-4611 lz4: LZ4_decompress_generic() integer overflow2014-06-24
CVE-2014-4611 — Improper Input Validation in Kernel | cvebase