LOW · 2.1

CVE-2014-9584

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local...

Vulnerability Description

The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local users to obtain sensitive information from kernel memory via a crafted iso9660 image.

CVSS Score

2.1

LOW

AV:L/AC:L/Au:N/C:P/I:N/A:N
Confidentiality
PARTIAL
Integrity
NONE
Availability
NONE

Affected Products

VendorProductVersions
LinuxLinux Kernel< 3.18.2
RedhatEnterprise Linux Aus6.6
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Eus6.6
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server Aus7.3
RedhatEnterprise Linux Server Eus7.1
RedhatEnterprise Linux Server Tus6.6
RedhatEnterprise Linux Workstation6.0
OpensuseEvergreen11.4
OpensuseOpensuse13.1
SuseLinux Enterprise Desktop12
SuseLinux Enterprise Real Time Extension11
SuseLinux Enterprise Server10
SuseLinux Enterprise Software Development Kit12
SuseLinux Enterprise Workstation Extension12
DebianDebian Linux7.0
CanonicalUbuntu Linux10.04
OracleLinux5

Related Weaknesses (CWE)

References

FAQ

What is CVE-2014-9584?

CVE-2014-9584 is a vulnerability with a CVSS score of 2.1 (LOW). The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel before 3.18.2 does not validate a length value in the Extensions Reference (ER) System Use Field, which allows local...

How severe is CVE-2014-9584?

CVE-2014-9584 has been rated LOW with a CVSS base score of 2.1/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2014-9584?

Check the references section above for vendor advisories and patch information. Affected products include: Linux Linux Kernel, Redhat Enterprise Linux Aus, Redhat Enterprise Linux Desktop, Redhat Enterprise Linux Eus, Redhat Enterprise Linux Server.