CVE-2017-7374: Use After Free
Last updated 29 November 2024
Other sources
Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic transform objects to be freed prematurely.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
debian/linuxto a version that resolves this vulnerability.Fixed in 5.10.223-1Fixed in 5.10.234-1Fixed in 6.1.129-1Fixed in 6.1.135-1Fixed in 6.12.22-1Fixed in 6.12.25-1 - Upgrade
Upgrade
Linux kernelto a version that resolves this vulnerability.Fixed in 4.10.7
Event History
Frequently Asked Questions
What is the severity of CVE-2017-7374?
The severity of CVE-2017-7374 is high with a severity value of 7.
How does CVE-2017-7374 affect Linux kernel versions?
CVE-2017-7374 affects Linux kernel versions before 4.10.7.
What is the impact of CVE-2017-7374?
The impact of CVE-2017-7374 is a use-after-free vulnerability that allows local users to cause a denial of service or possibly gain privileges.
How can I fix CVE-2017-7374?
To fix CVE-2017-7374, update the Linux kernel to version 4.10.7 or later.
Where can I find more information about CVE-2017-7374?
You can find more information about CVE-2017-7374 in the references section.