CVE-2017-18075: High severity linux kernel vulnerability
crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AFALG-based AEAD interface (CONFIGCRYPTOUSERAPIAEAD) and pcrypt (CONFIGCRYPTOPCRYPT) to cause a denial of service (kfree of an incorrect pointer) or possibly have unspecified other impact by executing a crafted sequence of system calls.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2017-18075.
What is the severity level of CVE-2017-18075?
CVE-2017-18075 has a severity level of medium.
Which software versions are affected by CVE-2017-18075?
The affected software versions include Linux kernel versions before 4.14.13.
How can a local user exploit this vulnerability?
A local user with access to the AF_ALG-based AEAD interface and pcrypt can exploit this vulnerability to cause a denial of service or possibly have unspecified impact.
Where can I find more information about CVE-2017-18075?
You can find more information about CVE-2017-18075 at the following references: [Git commit link](http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=d76c68109f37cb85b243a1cf0f40313afd2bae68), [GitHub commit link](https://github.com/torvalds/linux/commit/d76c68109f37cb85b243a1cf0f40313afd2bae68), [Kernel.org ChangeLog](https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.14.13).