The UDF filesystem implementation in the Linux kernel before 3.18.2 does not validate certain lengths, which allows local users to cause a denial of service (buffer over-read and system crash) via a crafted filesystem image, related to fs/udf/inode.c and fs/udf/symlink.c.
| Product | Vendor | Version |
|---|---|---|
| n/a | n/a | < 08d5e3e954537931c8da7428034808d202e98299 |
| n/a | n/a | <= 6.4.* |