Severity
5.5MEDIUMNVD
EPSS
0.0%
top 86.00%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 30
Latest updateJun 11

Description

The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages4 packages

Debianlinux/linux_kernel< 4.2.1-1+3
CVEListV5linux/linux_kernelLinux kernel
debiandebian/linux< linux 4.2.1-1 (bookworm)

Also affects: Enterprise Linux 7.0

Patches

🔴Vulnerability Details

2
GHSA
GHSA-6j2g-ffvm-v4hw: The rngapi_reset function in crypto/rng2022-05-14
OSV
CVE-2017-15116: The rngapi_reset function in crypto/rng2017-11-30

📋Vendor Advisories

2
Red Hat
kernel: Null pointer dereference in rngapi_reset function2017-08-28
Debian
CVE-2017-15116: linux - The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows ...2017

📄Research Papers

1
arXiv
Mono: Is Your "Clean" Vulnerability Dataset Really Solvable? Exposing and Trapping Undecidable Patches and Beyond2025-06-11

💬Community

2
Bugzilla
CVE-2017-15116 kernel: Null pointer dereference in rngapi_reset function [fedora-all]2017-11-30
Bugzilla
CVE-2017-15116 kernel: Null pointer dereference in rngapi_reset function2017-11-17