cbcvebase.
CVE-2014-5472
published 2014-09-01

CVE-2014-5472: The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable…

PriorityP413medium4CVSS 2.0
AVLACHAuNCNINAC
EPSS
0.51%
40.7th percentile
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry.

Affected

8 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.16.2-1 (bookworm)linux 3.16.2-1 (bookworm)
linuxlinux_kernel<= 3.16.1
linuxlinux_kernel
linuxlinux_kernel>= 0 < 3.16.2-13.16.2-1
linuxlinux_kernel>= 0 < 3.16.2-13.16.2-1
linuxlinux_kernel>= 0 < 3.16.2-13.16.2-1
linuxlinux_kernel>= 0 < 3.16.2-13.16.2-1
linuxlinux_kernel>= 0 < 3.13.0-36.633.13.0-36.63

CVSS provenance

nvdv2.04.0MEDIUMAV:L/AC:H/Au:N/C:N/I:N/A:C
osv4.3MEDIUM
vendor_ubuntu4.3MEDIUM
vendor_debian4.0MEDIUM
vendor_redhat4.0MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.