UBUNTU-CVE-2017-18075
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-18075
UBUNTU-CVE-2017-18075
Summary:
Details: crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_CRYPTO_PCRYPT) to cause a denial of service (kfree of an incorrect pointer) or possibly have unspecified other impact by executing a crafted sequence of system calls.
References: https://ubuntu.com/security/CVE-2017-18075, http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d76c68109f37cb85b243a1cf0f40313afd2bae68, https://github.com/torvalds/linux/commit/d76c68109f37cb85b243a1cf0f40313afd2bae68, https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.13, https://ubuntu.com/security/notices/USN-3619-1, https://ubuntu.com/security/notices/USN-3619-2, https://www.cve.org/CVERecord?id=CVE-2017-18075
Affected packages
Package
Name: linux-aws
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=trusty
Affected ranges
Type: ECOSYSTEM
Events:
