Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2014-9428 Details

Description

The batadv_frag_merge_packets function in net/batman-adv/fragmentation.c in the B.A.T.M.A.N. implementation in the Linux kernel through 3.18.1 uses an incorrect length field during a calculation of an amount of memory, which allows remote attackers to cause a denial of service (mesh-node system crash) via fragmented packets.

Metrics

CVSS 3.x Severity and Vector Strings:

No CVSS 3.x data is available for this CVE.

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://bugs.debian.org/774155 CVEThird Party Advisory
http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=5b6698b0e4a37053de35cc24ee695b98a7eb712b CVE
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147864.html CVEMailing ListThird Party Advisory
http://lists.fedoraproject.org/pipermail/package-announce/2015-January/147973.html CVEMailing ListThird Party Advisory
https://github.com/torvalds/linux/commit/5b6698b0e4a37053de35cc24ee695b98a7eb712b CVEPatchThird Party Advisory

see all 26 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-399Resource Management Errors[email protected]

Affected Products

ProductVersions
linux linux kernel
>= 3.13, < 3.14.30
>= 3.15, < 3.16.35
>= 3.17, < 3.18.4

CPE

  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

11 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2014-9428
NVD Published Date:
Jan 2, 2015
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]