The __udf_read_inode function in fs/udf/inode.c in the Linux kernel through 3.16.3 does not restrict the amount of ICB indirection, which allows physically proximate attackers to cause a denial of service (infinite loop or stack consumption) via a UDF filesystem with a crafted inode.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 3.16.0 | 3.16.0.x |
| linux / linux_kernel | 3.16.2 | 3.16.2.x |
| linux / linux_kernel | - | 3.16.3.x |
| linux / linux_kernel | 3.16.1 | 3.16.1.x |