cbcvebase.
CVE-2014-6410
published 2014-09-28

CVE-2014-6410: The __udf_read_inode function in fs/udf/inode.c in the Linux kernel through 3.16.3 does not restrict the amount of ICB indirection, which allows physically…

PriorityP417medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.51%
40.9th percentile
The __udf_read_inode function in fs/udf/inode.c in the Linux kernel through 3.16.3 does not restrict the amount of ICB indirection, which allows physically proximate attackers to cause a denial of service (infinite loop or stack consumption) via a UDF filesystem with a crafted inode.

Affected

10 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.16.5-1 (bookworm)linux 3.16.5-1 (bookworm)
linuxlinux_kernel<= 3.16.3
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel
linuxlinux_kernel>= 0 < 3.16.5-13.16.5-1
linuxlinux_kernel>= 0 < 3.16.5-13.16.5-1
linuxlinux_kernel>= 0 < 3.16.5-13.16.5-1
linuxlinux_kernel>= 0 < 3.16.5-13.16.5-1
linuxlinux_kernel>= 0 < 3.13.0-37.643.13.0-37.64

CVSS provenance

nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv6.9MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.