The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of service (NULL pointer dereference) via a crafted application.
Metrics
Affected Vendors & Products
References
History
No history.

Status: PUBLISHED
Assigner: mitre
Published: 2017-05-23T05:14:00Z
Updated: 2024-09-17T02:53:35.114Z
Reserved: 2017-05-23T00:00:00Z
Link: CVE-2017-9211

No data.

Status : Deferred
Published: 2017-05-23T05:29:00.247
Modified: 2025-04-20T01:37:25.860
Link: CVE-2017-9211
