SB2014090601 - Fedora 21 update for kernel
Published: September 6, 2014 Updated: April 24, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 2 secuirty vulnerabilities.
1) Resource management error (CVE-ID: CVE-2014-5471)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
Stack consumption vulnerability in the parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (uncontrolled recursion, and system crash or reboot) via a crafted iso9660 image with a CL entry referring to a directory entry that has a CL entry.
2) Input validation error (CVE-ID: CVE-2014-5472)
The vulnerability allows a remote non-authenticated attacker to perform a denial of service (DoS) attack.
The parse_rock_ridge_inode_internal function in fs/isofs/rock.c in the Linux kernel through 3.16.1 allows local users to cause a denial of service (unkillable mount process) via a crafted iso9660 image with a self-referential CL entry.
Remediation
Install update from vendor's website.