cbcvebase.
CVE-2014-5471
published 2014-09-01

CVE-2014-5471: Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to…

PriorityP414medium4CVSS 2.0
AVLACHAuNCNINAC
EPSS
0.51%
40.7th percentile
Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 image with a CL entry referring to a directory entry that has a CL entry.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.16.2-1 (bookworm)linux 3.16.2-1 (bookworm)
linuxlinux_kernel<= 3.16.1
linuxlinux_kernel
linuxlinux_kernel>= 0 < 3.16.2-13.16.2-1
linuxlinux_kernel>= 0 < 3.16.2-13.16.2-1
linuxlinux_kernel>= 0 < 3.16.2-13.16.2-1
linuxlinux_kernel>= 0 < 3.16.2-13.16.2-1
linuxlinux_kernel>= 0 < 3.13.0-36.633.13.0-36.63

CVSS provenance

nvdv2.04.0MEDIUMAV:L/AC:H/Au:N/C:N/I:N/A:C
osv4.3MEDIUM
vendor_ubuntu4.3MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.