CVE Published: 22/11/2017 |
CVE Updated: 05/08/2024 |
CVE Year: 2017 Source: redhat |
Vendor: n/a |
Product: Linux kernel since 3.13 up to 4.14 (not including) Status : PUBLISHED
CVE-2017-12193 Description
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demonstrated by the keyring key type, and key addition and link creation operations.