cbcvebase.
CVE-2015-4167
published 2015-08-05

CVE-2015-4167: The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values, which allows local users to cause a…

PriorityP416medium4.7CVSS 2.0
AVLACMAuNCNINAC
EPSS
0.43%
35.8th percentile
The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values, which allows local users to cause a denial of service (incorrect data representation or integer overflow, and OOPS) via a crafted UDF filesystem.

Affected

9 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
debiandebian_linux
debianlinux< linux 4.0.2-1 (bookworm)linux 4.0.2-1 (bookworm)
linuxlinux_kernel<= 3.19
linuxlinux_kernel>= 0 < 4.0.2-14.0.2-1
linuxlinux_kernel>= 0 < 4.0.2-14.0.2-1
linuxlinux_kernel>= 0 < 4.0.2-14.0.2-1
linuxlinux_kernel>= 0 < 4.0.2-14.0.2-1
linuxlinux_kernel>= 0 < 3.13.0-57.953.13.0-57.95

CVSS provenance

nvdv2.04.7MEDIUMAV:L/AC:M/Au:N/C:N/I:N/A:C
osv6.9MEDIUM
vendor_ubuntu6.9MEDIUM
vendor_debian4.7MEDIUM
vendor_redhat4.7MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.