UBUNTU-CVE-2017-9211
Dashboard / Vulnerabilities / UBUNTU-CVE-2017-9211
Summary:
Details: The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of service (NULL pointer dereference) via a crafted application.
References: https://ubuntu.com/security/CVE-2017-9211, https://git.kernel.org/linus/9933e113c2e87a9f46a40fde8dafbf801dca1ab9, http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9933e113c2e87a9f46a40fde8dafbf801dca1ab9, https://github.com/torvalds/linux/commit/9933e113c2e87a9f46a40fde8dafbf801dca1ab9, https://patchwork.kernel.org/patch/9718933/, https://www.cve.org/CVERecord?id=CVE-2017-9211
Affected packages
Package
Name: linux-gcp
Purl: pkg:deb/ubuntu/[email protected]?arch=source&distro=xenial
Affected ranges
Type: ECOSYSTEM
Events:
