cbcvebase.
CVE-2017-18075
published 2018-01-24

CVE-2017-18075: crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface…

PriorityP432high7.8CVSS 3.1
AVLACLPRLUINSUCHIHAH
EPSS
0.41%
33.6th percentile
crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_CRYPTO_PCRYPT) to cause a denial of service (kfree of an incorrect pointer) or possibly have unspecified other impact by executing a crafted sequence of system calls.

Affected

11 ranges
VendorProductVersion rangeFixed in
canonicalubuntu_linux
canonicalubuntu_linux
debianlinux< linux 4.14.13-1 (bookworm)linux 4.14.13-1 (bookworm)
linuxlinux_kernel>= 0 < 4.14.13-14.14.13-1
linuxlinux_kernel>= 0 < 4.14.13-14.14.13-1
linuxlinux_kernel>= 0 < 4.14.13-14.14.13-1
linuxlinux_kernel>= 0 < 4.14.13-14.14.13-1
linuxlinux_kernel>= 0 < 4.4.0-119.1434.4.0-119.143
linuxlinux_kernel>= 4.10 < 4.14.134.14.13
linuxlinux_kernel>= 4.2 < 4.4.1114.4.111
linuxlinux_kernel>= 4.5 < 4.9.764.9.76

CVSS provenance

nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
nvdv2.07.2HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
osv7.8HIGH
vendor_debian7.8HIGH
vendor_redhat7.8HIGH
vendor_ubuntu7.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.