Bugzilla will be upgraded to version 5.0 on a still to be determined date in the near future. The original upgrade date has been delayed.
Bug 1134099 - (CVE-2014-5471, CVE-2014-5472) CVE-2014-5471 CVE-2014-5472 kernel: isofs: unbound recursion when processing relocated directories
CVE-2014-5471 CVE-2014-5472 kernel: isofs: unbound recursion when processing ...
Status: CLOSED ERRATA
Product: Security Response
Classification: Other
Component: vulnerability (Show other bugs)
unspecified
All Linux
low Severity low
: ---
: ---
Assigned To: Red Hat Product Security
impact=low,public=20140826,reported=2...
: Security
Depends On: 1142268 1142269 1142270 1142271 1142272 1196304 1196305 1196306
Blocks: 1134101
  Show dependency treegraph
 
Reported: 2014-08-26 16:24 EDT by Martin Prpič
Modified: 2016-02-10 02:00 EST (History)
33 users (show)

See Also:
Fixed In Version:
Doc Type: Bug Fix
Doc Text:
It was found that the parse_rock_ridge_inode_internal() function of the Linux kernel's ISOFS implementation did not correctly check relocated directories when processing Rock Ridge child link (CL) tags. An attacker with physical access to the system could use a specially crafted ISO image to crash the system or, potentially, escalate their privileges on the system.
Story Points: ---
Clone Of:
Environment:
Last Closed: 2016-02-10 02:00:25 EST
Type: ---
Regression: ---
Mount Type: ---
Documentation: ---
CRM:
Verified Versions:
Category: ---
oVirt Team: ---
RHEL 7.3 requirements from Atomic Host:
Cloudforms Team: ---


Attachments (Terms of Use)


External Trackers
Tracker ID Priority Status Summary Last Updated
Red Hat Product Errata RHSA-2014:1318 normal SHIPPED_LIVE Moderate: Red Hat Enterprise MRG Realtime 2.5 security and enhancement update 2014-09-29 19:41:06 EDT
Red Hat Product Errata RHSA-2014:1997 normal SHIPPED_LIVE Important: kernel security and bug fix update 2014-12-16 19:12:55 EST
Red Hat Product Errata RHSA-2015:0102 normal SHIPPED_LIVE Important: kernel security and bug fix update 2015-01-28 19:02:51 EST
Red Hat Product Errata RHSA-2015:0695 normal SHIPPED_LIVE Important: kernel security and bug fix update 2015-03-17 14:39:19 EDT
Red Hat Product Errata RHSA-2015:0782 normal SHIPPED_LIVE Important: kernel security and bug fix update 2015-04-07 15:08:32 EDT
Red Hat Product Errata RHSA-2015:0803 normal SHIPPED_LIVE Important: kernel security and bug fix update 2015-04-14 13:00:51 EDT

  None (edit)
Description Martin Prpič 2014-08-26 16:24:49 EDT
It was found that the parse_rock_ridge_inode_internal() function of the Linux kernel's ISOFS implementation did not correctly check relocated directories when processing Rock Ridge child link (CL) tags. An attacker with physical access to the system could use a specially crafted ISO image to crash the system or, potentially, escalate their privileges on the system.

Upstream fix:
------------
   -> https://git.kernel.org/linus/410dd3cf4c9b36f27ed4542ee18b1af5e68645a4

CVE request:
------------
  -> http://seclists.org/oss-sec/2014/q3/450
Comment 1 Martin Prpič 2014-08-27 05:03:00 EDT
MITRE assigned two CVE numbers, CVE-2014-5471 and CVE-2014-5472, for this issue. More details here:

http://seclists.org/oss-sec/2014/q3/452
Comment 2 Josh Boyer 2014-08-27 20:36:03 EDT
Fedora has patched this on all relevant branches now.
Comment 3 Fedora Update System 2014-08-29 23:58:15 EDT
kernel-3.15.10-201.fc20 has been pushed to the Fedora 20 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 6 Prasad J Pandit 2014-09-16 09:16:28 EDT
Statement:

This issue affects the versions of the Linux kernel as shipped with Red Hat Enterprise Linux 5. Future kernel updates for Red Hat Enterprise Linux 5 may address this issue.
Comment 8 Fedora Update System 2014-09-23 01:00:18 EDT
kernel-3.16.2-300.fc21 has been pushed to the Fedora 21 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 9 errata-xmlrpc 2014-09-29 15:41:44 EDT
This issue has been addressed in the following products:

  MRG for RHEL-6 v.2

Via RHSA-2014:1318 https://rhn.redhat.com/errata/RHSA-2014-1318.html
Comment 10 Fedora Update System 2014-09-29 21:59:12 EDT
kernel-3.14.19-100.fc19 has been pushed to the Fedora 19 stable repository.  If problems still persist, please make note of it in this bug report.
Comment 11 Martin Prpič 2014-09-30 06:48:05 EDT
IssueDescription CVE-2014-5472:

It was found that the parse_rock_ridge_inode_internal() function of the Linux kernel's ISOFS implementation did not correctly check relocated directories when processing Rock Ridge child link (CL) tags. An attacker with physical access to the system could use a specially crafted ISO image to crash the system or, potentially, escalate their privileges on the system.

IssueDescription CVE-2014-5471:

It was found that the parse_rock_ridge_inode_internal() function of the Linux kernel's ISOFS implementation did not correctly check relocated directories when processing Rock Ridge child link (CL) tags. An attacker with physical access to the system could use a specially crafted ISO image to crash the system or, potentially, escalate their privileges on the system.
Comment 12 errata-xmlrpc 2014-12-16 14:13:24 EST
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6

Via RHSA-2014:1997 https://rhn.redhat.com/errata/RHSA-2014-1997.html
Comment 13 errata-xmlrpc 2015-01-28 14:04:56 EST
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 7

Via RHSA-2015:0102 https://rhn.redhat.com/errata/RHSA-2015-0102.html
Comment 15 errata-xmlrpc 2015-03-17 10:40:04 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6.2 AUS

Via RHSA-2015:0695 https://rhn.redhat.com/errata/RHSA-2015-0695.html
Comment 16 errata-xmlrpc 2015-04-07 11:12:38 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6.5 EUS - Server and Compute Node Only

Via RHSA-2015:0782 https://rhn.redhat.com/errata/RHSA-2015-0782.html
Comment 17 errata-xmlrpc 2015-04-14 09:09:05 EDT
This issue has been addressed in the following products:

  Red Hat Enterprise Linux 6.4 AUS - Server Only

Via RHSA-2015:0803 https://rhn.redhat.com/errata/RHSA-2015-0803.html

Note You need to log in before you can comment on or make changes to this bug.