CVE-2017-7374

Description

Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic transform objects to be freed prematurely.

Risk Information

Base Score
7.8
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
0.315

Associated Vulnerability

VulnerabilityOS Platform
Linux kernel (USN-3326-1) linux-image-virtual_4.8.0.56.69_i386.debLinux
Linux kernel (USN-3326-1) linux-image-virtual_4.8.0.56.69_amd64.debLinux
Linux kernel (USN-3326-1) linux-image-4.8.0-56-generic_4.8.0-56.61_i386.debLinux
Linux kernel (USN-3326-1) linux-image-4.8.0-56-generic_4.8.0-56.61_amd64.debLinux
Linux kernel (USN-3326-1) linux-image-4.8.0-56-lowlatency_4.8.0-56.61_i386.debLinux
Linux kernel (USN-3326-1) linux-image-4.8.0-56-lowlatency_4.8.0-56.61_amd64.debLinux
Linux hardware enablement (HWE) kernel (USN-3333-1) linux-image-4.8.0-56-generic_4.8.0-56.61~16.04.1_i386.debLinux
Linux hardware enablement (HWE) kernel (USN-3333-1) linux-image-4.8.0-56-generic_4.8.0-56.61~16.04.1_amd64.debLinux
Linux hardware enablement (HWE) kernel (USN-3333-1) linux-image-generic-hwe-16.04_4.8.0.56.27_i386.debLinux
Linux hardware enablement (HWE) kernel (USN-3333-1) linux-image-generic-hwe-16.04_4.8.0.56.27_amd64.debLinux
Linux hardware enablement (HWE) kernel (USN-3333-1) linux-image-4.8.0-56-lowlatency_4.8.0-56.61~16.04.1_i386.debLinux
Linux hardware enablement (HWE) kernel (USN-3333-1) linux-image-4.8.0-56-lowlatency_4.8.0-56.61~16.04.1_amd64.debLinux
Linux hardware enablement (HWE) kernel (USN-3333-1) linux-image-lowlatency-hwe-16.04_4.8.0.56.27_i386.debLinux
Linux hardware enablement (HWE) kernel (USN-3333-1) linux-image-lowlatency-hwe-16.04_4.8.0.56.27_amd64.debLinux
Linux kernel (USN-3342-1) linux-image-4.8.0-58-generic_4.8.0-58.63_i386.debLinux
Linux kernel (USN-3342-1) linux-image-4.8.0-58-generic_4.8.0-58.63_amd64.debLinux
Linux kernel (USN-3342-1) linux-image-4.8.0-58-lowlatency_4.8.0-58.63_i386.debLinux
Linux kernel (USN-3342-1) linux-image-4.8.0-58-lowlatency_4.8.0-58.63_amd64.debLinux
Linux hardware enablement (HWE) kernel (USN-3342-2) linux-image-4.8.0-58-generic_4.8.0-58.63~16.04.1_i386.debLinux
Linux hardware enablement (HWE) kernel (USN-3342-2) linux-image-4.8.0-58-generic_4.8.0-58.63~16.04.1_amd64.debLinux
Linux hardware enablement (HWE) kernel (USN-3342-2) linux-image-4.8.0-58-lowlatency_4.8.0-58.63~16.04.1_i386.debLinux
Linux hardware enablement (HWE) kernel (USN-3342-2) linux-image-4.8.0-58-lowlatency_4.8.0-58.63~16.04.1_amd64.debLinux
Linux kernel (LSN-0026-1) linux-image-generic_4.4.0.87.93_i386.debLinux
Linux kernel (LSN-0026-1) linux-image-generic_4.4.0.87.93_amd64.debLinux
Linux kernel (LSN-0026-1) linux-image-lowlatency_4.4.0.87.93_i386.debLinux
Linux kernel (LSN-0026-1) linux-image-lowlatency_4.4.0.87.93_amd64.debLinux
Linux kernel (LSN-0026-1) linux-image-4.4.0-87-generic_4.4.0-87.110_i386.debLinux
Linux kernel (LSN-0026-1) linux-image-4.4.0-87-generic_4.4.0-87.110_amd64.debLinux
Linux kernel (LSN-0026-1) linux-image-4.4.0-87-lowlatency_4.4.0-87.110_i386.debLinux
Linux kernel (LSN-0026-1) linux-image-4.4.0-87-lowlatency_4.4.0-87.110_amd64.debLinux

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234