CVE-2017-12153 — NULL Pointer Dereference in Linux
Severity
4.4MEDIUMNVD
OSV7.8OSV6.5
EPSS
0.0%
top 96.22%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedSep 21
Latest updateMay 13
Description
A security flaw was discovered in the nl80211_set_rekey_data() function in net/wireless/nl80211.c in the Linux kernel through 4.13.3. This function does not check whether the required attributes are present in a Netlink request. This request can be issued by a user with the CAP_NET_ADMIN capability and may result in a NULL pointer dereference and system crash.
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:N/A:HExploitability: 0.8 | Impact: 3.6
Affected Packages4 packages
Also affects: Debian Linux 8.0, 9.0, Ubuntu Linux 12.04, 14.04
Patches
🔴Vulnerability Details
6📋Vendor Advisories
7💬Community
3Bugzilla▶
CVE-2017-15087 samba: Server memory information leak over SMB1 (incomplete fix for CVE-2017-12163)↗2017-10-24
Bugzilla
▶