CVE Database
/

CVE-2017-12193

Back to search

CVE-2017-12193

Published: Nov 22, 2017

Modified: Aug 5, 2024

PUBLISHED

Description

The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demonstrated by the keyring key type, and key addition and link creation operations.

VendorProductVersions

n/a

Linux kernel since 3.13 up to 4.14 (not including)

affected
Linux kernel since 3.13 up to 4.14 (not including)

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now