CVE-2014-5471: Medium severity Linux Linux kernel vulnerability
It was found that the parserockridgeinodeinternal() function of the Linux kernel's ISOFS implementation did not correctly check relocated directories when processing Rock Ridge child link (CL) tags. An attacker with physical access to the system could use a specially crafted ISO image to crash the system or, potentially, escalate their privileges on the system.
Other sources
Stack consumption vulnerability in the parserockridgeinodeinternal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 image with a CL entry referring to a directory entry that has a CL entry.
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-5471?
CVE-2014-5471 is rated as a moderate severity vulnerability that can lead to system crashes through specially crafted ISO images.
How do I fix CVE-2014-5471?
To mitigate CVE-2014-5471, update your Linux kernel to one of the affected versions that contain the security patch.
Who is affected by CVE-2014-5471?
CVE-2014-5471 affects users of the Linux kernel versions prior to the patched versions listed in the vulnerability report.
What type of vulnerability is CVE-2014-5471?
CVE-2014-5471 is a vulnerability in the ISOFS implementation of the Linux kernel related to improper handling of Rock Ridge child link tags.
Can CVE-2014-5471 be exploited remotely?
CVE-2014-5471 requires physical access to the vulnerable system for exploitation, making it less likely to be exploited remotely.