High severity7.3NVD Advisory· Published Jul 3, 2014· Updated May 6, 2026
CVE-2014-4608
CVE-2014-4608
Description
Multiple integer overflows in the lzo1x_decompress_safe function in lib/lzo/lzo1x_decompress_safe.c in the LZO decompressor in the Linux kernel before 3.15.2 allow context-dependent attackers to cause a denial of service (memory corruption) via a crafted Literal Run. NOTE: the author of the LZO algorithms says "the Linux kernel is *not* affected; media hype.
Affected products
8cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*+ 3 more
- cpe:2.3:o:canonical:ubuntu_linux:10.04:*:*:*:-:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:12.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.04:*:*:*:esm:*:*:*
- cpe:2.3:o:canonical:ubuntu_linux:14.10:*:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_real_time_extension:11:sp3:*:*:*:*:*:*
- cpe:2.3:o:suse:linux_enterprise_server:11:sp2:*:*:ltss:*:*:*
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
21- github.com/torvalds/linux/commit/206a81c18401c0cde6e579164f752c4b147324cenvdPatchThird Party Advisory
- blog.securitymouse.com/2014/06/raising-lazarus-20-year-old-bug-that.htmlnvdThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2015-03/msg00010.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2015-03/msg00025.htmlnvdMailing ListThird Party Advisory
- lists.opensuse.org/opensuse-security-announce/2015-04/msg00015.htmlnvdMailing ListThird Party Advisory
- rhn.redhat.com/errata/RHSA-2015-0062.htmlnvdThird Party Advisory
- secunia.com/advisories/60011nvdThird Party Advisory
- secunia.com/advisories/60174nvdThird Party Advisory
- secunia.com/advisories/62633nvdThird Party Advisory
- www.kernel.org/pub/linux/kernel/v3.x/ChangeLog-3.15.2nvdRelease NotesVendor Advisory
- www.oberhumer.com/opensource/lzo/nvdThird Party Advisory
- www.openwall.com/lists/oss-security/2014/06/26/21nvdMailing ListThird Party Advisory
- www.securityfocus.com/bid/68214nvdThird Party AdvisoryVDB Entry
- www.ubuntu.com/usn/USN-2416-1nvdThird Party Advisory
- www.ubuntu.com/usn/USN-2417-1nvdThird Party Advisory
- www.ubuntu.com/usn/USN-2418-1nvdThird Party Advisory
- www.ubuntu.com/usn/USN-2419-1nvdThird Party Advisory
- www.ubuntu.com/usn/USN-2420-1nvdThird Party Advisory
- www.ubuntu.com/usn/USN-2421-1nvdThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- www.securitymouse.com/lms-2014-06-16-2nvdBroken Link
News mentions
0No linked articles in our index yet.