VOMIT (go/vomit) has received an external vulnerability report for the Linux kernel.
Advisory: CVE-2017-9211
Details: http://vomit.googleplex.com/advisory?id=CVE/CVE-2017-9211
CVSS severity score: 4.9/10.0
Description:
The crypto_skcipher_init_tfm function in crypto/skcipher.c in the Linux kernel through 4.11.2 relies on a setkey function that lacks a key-size check, which allows local users to cause a denial of service (NULL pointer dereference) via a crafted application.
This bug was filed by http://go/vomit
Please contact us at vomit-team@google.com if you need any assistance.
Comment 1 by lgar...@chromium.org
, Jun 9 2017Owner: groeck@chromium.org
Status: Assigned (was: Untriaged)