CVE-2014-9428

Linux Kernel 3.13-3.14.29 - Denial of Service via B.A.T.M.A.N. Fragmented Packets

Title source: llm
STIX 2.1

Description

The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses an incorrect length field during a calculation of an amount of memory, which allows remote attackers to cause a denial of service (mesh-node system crash) via fragmented packets.

References (13)

Core 13
Core References
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147864.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2515-1
Mailing List, Third Party Advisory mailing-list x_refsource_mlist
http://www.openwall.com/lists/oss-security/2014/12/31/7
Third Party Advisory mailing-list x_refsource_mlist
http://www.spinics.net/lists/netdev/msg309425.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2518-1
Broken Link vendor-advisory x_refsource_mandriva
http://www.mandriva.com/security/advisories?name=MDVSA-2015:058
Mailing List, Third Party Advisory vendor-advisory x_refsource_fedora
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147973.html
Third Party Advisory x_refsource_confirm
http://bugs.debian.org/774155
Third Party Advisory mailing-list x_refsource_mlist
https://lists.open-mesh.org/pipermail/b.a.t.m.a.n/2014-November/012561.html
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2517-1
Third Party Advisory vendor-advisory x_refsource_ubuntu
http://www.ubuntu.com/usn/USN-2516-1

Scores

EPSS 0.0536
EPSS Percentile 91.9%

Details

CWE
CWE-399
Status published
Products (1)
linux/linux_kernel 3.13 - 3.14.30
Published Jan 02, 2015
Tracked Since Feb 18, 2026