cbcvebase.
CVE-2014-4611
published 2014-07-03

CVE-2014-4611: Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in…

PriorityP429medium5CVSS 2.0
AVNACLAuNCNINAP
EPSS
8.10%
94.2th percentile
Integer overflow in the LZ4 algorithm implementation, as used in Yann Collet LZ4 before r118 and in the lz4_uncompress function in lib/lz4/lz4_decompress.c in the Linux kernel before 3.15.2, on 32-bit platforms might allow context-dependent attackers to cause a denial of service (memory corruption) or possibly have unspecified other impact via a crafted Literal Run that would be improperly handled by programs not complying with an API limitation, a different vulnerability than CVE-2014-4715.

Affected

14 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.14.9-1 (bookworm)linux 3.14.9-1 (bookworm)
debianlz4< lz4 0.0~r119-1 (bookworm)lz4 0.0~r119-1 (bookworm)
debianlz4< linux 3.14.9-1 (bookworm)linux 3.14.9-1 (bookworm)
linuxlinux_kernel< 3.15.23.15.2
linuxlinux_kernel>= 0 < 3.14.9-13.14.9-1
linuxlinux_kernel>= 0 < 3.14.9-13.14.9-1
linuxlinux_kernel>= 0 < 3.14.9-13.14.9-1
linuxlinux_kernel>= 0 < 3.14.9-13.14.9-1
linuxlinux_kernel>= 0 < 3.13.0-32.573.13.0-32.57
lz4_projectlz4>= 0 < 0.0~r119-10.0~r119-1
lz4_projectlz4>= 0 < 0.0~r119-10.0~r119-1
lz4_projectlz4>= 0 < 0.0~r119-10.0~r119-1
lz4_projectlz4>= 0 < 0.0~r119-10.0~r119-1
yann_colletlz4<= r118

CVSS provenance

nvdv2.05.0MEDIUMAV:N/AC:L/Au:N/C:N/I:N/A:P
osv5.0MEDIUM
vendor_redhat5.5MEDIUM
vendor_debian5.0LOW
vendor_ubuntu2.9LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.