CVE-2014-5472: Input Validation
It was found that the parserockridgeinodeinternal() function of the Linux kernel's ISOFS implementation did not correctly check relocated directories when processing Rock Ridge child link (CL) tags. An attacker with physical access to the system could use a specially crafted ISO image to crash the system or, potentially, escalate their privileges on the system.
Other sources
The parserockridgeinodeinternal function in fs/isofs/rock.c in the ...
— Debian
Affected Software
Remediation
Event History
Parent advisories
This vulnerability appears in the following advisories.
Frequently Asked Questions
What is the severity of CVE-2014-5472?
CVE-2014-5472 is classified as a medium severity vulnerability.
How do I fix CVE-2014-5472?
To fix CVE-2014-5472, update to the latest kernel version as specified in your operating system's security patches.
Who is affected by CVE-2014-5472?
CVE-2014-5472 affects systems running specific versions of the Linux kernel, particularly those prior to the patched versions.
What type of attack does CVE-2014-5472 enable?
CVE-2014-5472 could allow an attacker with physical access to the system to crash the system using a specially crafted ISO image.
Is physical access required for exploiting CVE-2014-5472?
Yes, exploiting CVE-2014-5472 requires physical access to the affected system.