vulnerability
SUSE: CVE-2017-18075: SUSE Linux Security Advisory
Severity | CVSS | Published | Added | Modified |
---|---|---|---|---|
7 | (AV:L/AC:L/Au:N/C:C/I:C/A:C) | Jan 24, 2018 | May 20, 2018 | Feb 4, 2022 |
Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
Jan 24, 2018
Added
May 20, 2018
Modified
Feb 4, 2022
Description
crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_CRYPTO_PCRYPT) to cause a denial of service (kfree of an incorrect pointer) or possibly have unspecified other impact by executing a crafted sequence of system calls.
Solution(s)
suse-upgrade-cluster-md-kmp-defaultsuse-upgrade-dlm-kmp-defaultsuse-upgrade-gfs2-kmp-defaultsuse-upgrade-kernel-azure-basesuse-upgrade-kernel-defaultsuse-upgrade-kernel-default-extrasuse-upgrade-kernel-default-mansuse-upgrade-kernel-devel-azuresuse-upgrade-kernel-docssuse-upgrade-kernel-obs-buildsuse-upgrade-kernel-source-azuresuse-upgrade-ocfs2-kmp-default
References
- SUSE-SUSE-SU-2018:0568-1
- SUSE-SUSE-SU-2018:0572-1
- SUSE-SUSE-SU-2018:0573-1
- SUSE-SUSE-SU-2018:0574-1
- SUSE-SUSE-SU-2018:0575-1
- SUSE-SUSE-SU-2018:0576-1
- SUSE-SUSE-SU-2018:0577-1
- SUSE-SUSE-SU-2018:0578-1
- SUSE-SUSE-SU-2018:0579-1
- SUSE-SUSE-SU-2018:0582-1
- SUSE-SUSE-SU-2018:0584-1
- SUSE-SUSE-SU-2018:0586-1
- SUSE-SUSE-SU-2018:0590-1
- SUSE-SUSE-SU-2018:0591-1
- SUSE-SUSE-SU-2018:0592-1
- SUSE-SUSE-SU-2018:0593-1
- SUSE-SUSE-SU-2018:0594-1
- SUSE-SUSE-SU-2018:0595-1
- SUSE-SUSE-SU-2018:0596-1
- SUSE-SUSE-SU-2018:0597-1
- UBUNTU-USN-3619-1
- UBUNTU-USN-3619-2
- NVD-CVE-2017-18075

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.