CVE-2017-9211
published 2017-05-23CVE-2017-9211: The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which…
PriorityP417medium5.5CVSS 3.0
AVLACLPRLUINSUCNINAH
EPSS
0.39%
31.9th percentile
The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of service (NULL pointer dereference) via a crafted application.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | linux | < linux 4.9.30-1 (bookworm) | linux 4.9.30-1 (bookworm) |
| linux | linux_kernel | <= 4.11.2 | — |
| linux | linux_kernel | >= 0 < 4.9.30-1 | 4.9.30-1 |
| linux | linux_kernel | >= 0 < 4.9.30-1 | 4.9.30-1 |
| linux | linux_kernel | >= 0 < 4.9.30-1 | 4.9.30-1 |
| linux | linux_kernel | >= 0 < 4.9.30-1 | 4.9.30-1 |
CVSS provenance
nvdv3.05.5MEDIUMCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
nvdv2.04.9MEDIUMAV:L/AC:L/Au:N/C:N/I:N/A:C
osv5.5MEDIUM
vendor_debian5.5MEDIUM
vendor_redhat5.5MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-x4xp-29gp-7qw9: The crypto_skcipher_init_tfm function in crypto/skcipher
ghsa_unreviewed·2022-05-17
CVE-2017-9211 [MEDIUM] CWE-476 GHSA-x4xp-29gp-7qw9: The crypto_skcipher_init_tfm function in crypto/skcipher
The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of service (NULL pointer dereference) via a crafted application.
OSV
CVE-2017-9211: The crypto_skcipher_init_tfm function in crypto/skcipher
osv·2017-05-23·CVSS 5.5
CVE-2017-9211 [MEDIUM] CVE-2017-9211: The crypto_skcipher_init_tfm function in crypto/skcipher
The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of service (NULL pointer dereference) via a crafted application.
Red Hat
kernel: Null pointer dereference due to missing key-size check in setkey function
vendor_redhat·2017-05-09·CVSS 5.5
CVE-2017-9211 [MEDIUM] CWE-476 kernel: Null pointer dereference due to missing key-size check in setkey function
kernel: Null pointer dereference due to missing key-size check in setkey function
The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of service (NULL pointer dereference) via a crafted application.
The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of service (NULL pointer dereference) via a crafted application.
Package: kernel (Red Hat Enterprise Linux 5) - Not affected
Package: kernel (Red Hat Enterprise Linux 6) - Not affected
Package: kernel (Red Hat Enterprise Linux 7) - Affected
Package: kernel-rt
Debian
CVE-2017-9211: linux - The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel t...
vendor_debian·2017·CVSS 5.5
CVE-2017-9211 [MEDIUM] CVE-2017-9211: linux - The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel t...
The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of service (NULL pointer dereference) via a crafted application.
Scope: local
bookworm: resolved (fixed in 4.9.30-1)
bullseye: resolved (fixed in 4.9.30-1)
forky: resolved (fixed in 4.9.30-1)
sid: resolved (fixed in 4.9.30-1)
trixie: resolved (fixed in 4.9.30-1)
No detection rules found.
No public exploits indexed.
arXiv
To Err is Machine: Vulnerability Detection Challenges LLM Reasoning
arxiv_fulltext·2025-01-07
To Err is Machine: Vulnerability Detection Challenges LLM Reasoning
## Abstract
In this paper, we present a challenging code reasoning task: vulnerability detection. Large Language Models (LLMs) have shown promising results in natural-language and math reasoning, but state-of-the-art (SOTA) models reported only 54.5% Balanced Accuracy in our vulnerability detection evaluation, even those models pre-trained on large amounts of source code.
Our error analysis on LLM responses shows that the models struggle to reason about the code semantics relevant to identifying vulnerabilities, especially subtle semantic differences caused by small textual changes.
We explored prominent models and training settings to understand their effects on vulnerability detection performance --- including better prompts, larger models, more pre-training data, and fine-tuning ---
Bugzilla
CVE-2017-9211 kernel: Null pointer dereference due to missing key-size check in setkey function [fedora-all]
bugzilla·2017-05-23·CVSS 5.5
CVE-2017-9211 [MEDIUM] CVE-2017-9211 kernel: Null pointer dereference due to missing key-size check in setkey function [fedora-all]
CVE-2017-9211 kernel: Null pointer dereference due to missing key-size check in setkey function [fedora-all]
This is an automatically created tracking bug! It was created to ensure
that one or more security vulnerabilities are fixed in affected versions
of fedora-all.
For comments that are specific to the vulnerability please use bugs filed
against the "Security Response" product referenced in the "Blocks" field.
For more information see:
http://fedoraproject.org/wiki/Security/TrackingBugs
When submitting as an update, use the fedpkg template provided in the next
comment(s). This will include the bug IDs of this tracking bug as well as
the relevant top-level CVE bugs.
Please also mention the CVE IDs being fixed in the RPM changelog and the
fedpkg commit message.
NOTE: this issue affe
Bugzilla
CVE-2017-9211 kernel: Null pointer dereference due to missing key-size check in setkey function
bugzilla·2017-05-23·CVSS 5.5
CVE-2017-9211 [MEDIUM] CVE-2017-9211 kernel: Null pointer dereference due to missing key-size check in setkey function
CVE-2017-9211 kernel: Null pointer dereference due to missing key-size check in setkey function
The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of service (NULL pointer dereference) via a crafted application.
Upstream patch:
https://git.kernel.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/crypto?id=9933e113c2e87a9f46a40fde8dafbf801dca1ab9
Discussion:
Created kernel tracking bugs for this issue:
Affects: fedora-all [bug 1454759]
---
This was fixed for fedora with the 4.11.4 stable updates.
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9933e113c2e87a9f46a40fde8dafbf801dca1ab9https://github.com/torvalds/linux/commit/9933e113c2e87a9f46a40fde8dafbf801dca1ab9https://patchwork.kernel.org/patch/9718933/http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=9933e113c2e87a9f46a40fde8dafbf801dca1ab9https://github.com/torvalds/linux/commit/9933e113c2e87a9f46a40fde8dafbf801dca1ab9https://patchwork.kernel.org/patch/9718933/
2017-05-23
Published