UBUNTU-CVE-2014-9644
Dashboard / Vulnerabilities / UBUNTU-CVE-2014-9644
UBUNTU-CVE-2014-9644
Summary:
Details: The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.
References: https://ubuntu.com/security/CVE-2014-9644, https://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=4943ba16bbc2, https://ubuntu.com/security/notices/USN-2513-1, https://ubuntu.com/security/notices/USN-2514-1, https://ubuntu.com/security/notices/USN-2543-1, https://ubuntu.com/security/notices/USN-2544-1, https://ubuntu.com/security/notices/USN-2545-1, https://ubuntu.com/security/notices/USN-2546-1, https://www.cve.org/CVERecord?id=CVE-2014-9644
Affected packages
Package
Name: linux
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
