Return to CVE list

CVE-2015-8970

5.5
Medium

CVE-2015-8970

secalert@redhat.com
Modified

Description

crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted application that does not supply a key, related to the lrw_crypt function in crypto/lrw.c.

Exploits

No known exploits found for this CVE.

Search Exploit-DB

References

af854a3a-2127-422b-91ae-364da2661108
http://www.securityfocus.com/bid/94217
af854a3a-2127-422b-91ae-364da2661108
https://access.redhat.com/errata/RHSA-2017:1842
af854a3a-2127-422b-91ae-364da2661108
https://access.redhat.com/errata/RHSA-2017:2077
af854a3a-2127-422b-91ae-364da2661108
https://access.redhat.com/errata/RHSA-2017:2437
af854a3a-2127-422b-91ae-364da2661108
https://access.redhat.com/errata/RHSA-2017:2444
af854a3a-2127-422b-91ae-364da2661108
https://bugzilla.redhat.com/show_bug.cgi?id=1386286