Lucene search

K
f5F5F5:K17321
HistorySep 25, 2015 - 12:00 a.m.

K17321 : Linux kernel UDF vulnerability CVE-2015-4167

2015-09-2500:00:00
my.f5.com
37

6.9 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

Security Advisory Description

The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.19.1 does not validate certain length values, which allows local users to cause a denial of service (incorrect data representation or integer overflow, and OOPS) via a crafted UDF filesystem. (CVE-2015-4167)

Impact

An authenticated user may be able to impact the availability of the BIG-IP system and cause a denial-of-service (DoS). This vulnerability is considered local, as it is exploitable only by an authenticated user accessing the system using the command line. In addition, the udf kernel module must be loaded in order for the BIG-IP system to be vulnerable to this issue. The BIG-IP system does not load theudf kernel module by default.