Lucene search

K
f5F5F5:K17447
HistoryOct 16, 2015 - 12:00 a.m.

K17447 : Linux kernel UDF vulnerabilities CVE-2014-9728, CVE-2014-9729, and CVE-2014-9730

2015-10-1600:00:00
my.f5.com
20

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%

Security Advisory Description

The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows local users to cause a denial of service (buffer over-read and system crash) via a crafted filesystem image, related to fs/udf/inode.c and fs/udf/symlink.c.

The udf_read_inode function in fs/udf/inode.c in the Linux kernel before 3.18.2 does not ensure a certain data-structure size consistency, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.

The udf_pc_to_char function in fs/udf/symlink.c in the Linux kernel before 3.18.2 relies on component lengths that are unused, which allows local users to cause a denial of service (system crash) via a crafted UDF filesystem image.

Impact

An authenticated attacker must have the capability to load the vulnerable UDF kernel module and mount a crafted UDF filesystem image in order to cause a denial-of-service on the affected F5 products. By default, the vulnerable UDF kernel module is not loaded and not used by the affected F5 products.

5.5 Medium

AI Score

Confidence

High

0.0004 Low

EPSS

Percentile

10.1%