CVE-2014-9584: Input Validation
Last updated 24 July 2024
Other sources
Linux kernel built with the iso9660 file system(CONFIGISO9660FS) support is vulnerable to an information leakage flaw. This could occur while accessing data on an iso9660 image with RockRidge extension reference(ER) records.
An unprivileged user/process could use this flaw to leak (=~255)kernel memory bytes.
Upstream fix: ------------- -> https://git.kernel.org/linus/4e2024624e678f0ebb916e6192bd23c1f9fdf696
— Red Hat
The parserockridgeinodeinternal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.
— Launchpad
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2014-9584?
CVE-2014-9584 is considered to be an information leakage vulnerability that could be exploited by unprivileged users.
How do I fix CVE-2014-9584?
To fix CVE-2014-9584, upgrade to a patched version of the Linux kernel, specifically any version that incorporates the fixes beyond 3.18.2.
What systems are affected by CVE-2014-9584?
CVE-2014-9584 affects various Linux distributions including Red Hat Enterprise Linux, SUSE Linux, and Debian across multiple versions.
Can unprivileged users exploit CVE-2014-9584?
Yes, unprivileged users can exploit CVE-2014-9584 to leak sensitive information from iso9660 images.
Is there a specific patch version for CVE-2014-9584?
Yes, the resolved versions include Linux kernel versions such as 5.10.223-1, 5.10.226-1, and others listed by the respective distributions.