crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted application that does not supply a key, related to the lrw_crypt function in crypto/lrw.c.
CVSS Details
- CVSS 3.1 Base Score: 5.5
- CVSS 3.0 Vector: (CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade kernel-rtUpgrade kernel | Aug 28, 2019 | Nov 28, 2016 |
| Debian | — | Upgrade linux | Jul 30, 2024 | Nov 28, 2016 |
| Oracle_linux | — | Upgrade kernel | Jul 22, 2024 | Dec 17, 2015 |
| Redhat_linux | — | Upgrade kernel-rtUpgrade kernel | Aug 3, 2017 | Nov 27, 2016 |
| Suse | — | Upgrade kernel-docsUpgrade kernel-default | Feb 18, 2017 | Nov 27, 2016 |
| Ubuntu | — | Upgrade linux-lts-vividUpgrade linux-armadaxpUpgrade linuxUpgrade linux-ti-omap4 | Nov 19, 2024 | Nov 28, 2016 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub