crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted application that does not supply a key, related to the lrw_crypt function in crypto/lrw.c.
Product | Vendor | Version |
---|---|---|
n/a | n/a | b38c6e0bd5b5e439ecebdc0df599d573c2f610f8 |