Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
A flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was being dropped when each af_alg_ctx was freed instead of when the aead_tfm was freed. This can cause the null skcipher to be freed while it is still in use leading to a local user being able to crash the system or possibly escalate privileges.
CVSS Information
N/A
Vulnerability Type
释放后使用
Vulnerability Title
Linux kernel crypto子系统安全漏洞
Vulnerability Description
Linux kernel是美国Linux基金会发布的开源操作系统Linux所使用的内核。crypto subsystem是其中的一个加密子系统。 Linux kerne 4.15-rc4之前版本中的crypto子系统存在安全漏洞。本地攻击者可利用该漏洞造成系统崩溃并可能提升权限。
CVSS Information
N/A
Vulnerability Type
N/A