cbcvebase.
CVE-2014-9428
published 2015-01-02

CVE-2014-9428: The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses an…

PriorityP338high7.8CVSS 2.0
AVNACLAuNCNINAC
EPSS
5.36%
91.8th percentile
The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses an incorrect length field during a calculation of an amount of memory, which allows remote attackers to cause a denial of service (mesh-node system crash) via fragmented packets.

Affected

11 ranges
VendorProductVersion rangeFixed in
debianlinux< linux 3.16.7-ckt4-1 (bookworm)linux 3.16.7-ckt4-1 (bookworm)
linuxlinux_kernel>= 0 < 3.16.7-ckt4-13.16.7-ckt4-1
linuxlinux_kernel>= 0 < 3.16.7-ckt4-13.16.7-ckt4-1
linuxlinux_kernel>= 0 < 3.16.7-ckt4-13.16.7-ckt4-1
linuxlinux_kernel>= 0 < 3.16.7-ckt4-13.16.7-ckt4-1
linuxlinux_kernel>= 0 < 3.13.0-46.773.13.0-46.77
linuxlinux_kernel>= 0 < 3.13.0-46.753.13.0-46.75
linuxlinux_kernel>= 0 < 3.13.0-46.763.13.0-46.76
linuxlinux_kernel>= 3.13 < 3.14.303.14.30
linuxlinux_kernel>= 3.15 < 3.16.353.16.35
linuxlinux_kernel>= 3.17 < 3.18.43.18.4

CVSS provenance

nvdv2.07.8HIGHAV:N/AC:L/Au:N/C:N/I:N/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu2.1LOW
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.