← Back to CVEs
CVE-2017-7374
HIGH7.8
Description
Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic transform objects to be freed prematurely.
CVE Details
CVSS v3.1 Score7.8
SeverityHIGH
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack VectorLOCAL
ComplexityLOW
Privileges RequiredLOW
User InteractionNONE
Published3/31/2017
Last Modified4/20/2025
Sourcenvd
Honeypot Sightings0
Affected Products
linux:linux_kernel
Weaknesses (CWE)
CWE-416CWE-476
References
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1b53cf9815bb4744958d41f3795d5d5a1d365e2d(cve@mitre.org)
http://www.securityfocus.com/bid/97308(cve@mitre.org)
https://source.android.com/security/bulletin/2017-10-01(cve@mitre.org)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=1b53cf9815bb4744958d41f3795d5d5a1d365e2d(af854a3a-2127-422b-91ae-364da2661108)
http://www.securityfocus.com/bid/97308(af854a3a-2127-422b-91ae-364da2661108)
https://github.com/torvalds/linux/commit/1b53cf9815bb4744958d41f3795d5d5a1d365e2d(af854a3a-2127-422b-91ae-364da2661108)
https://source.android.com/security/bulletin/2017-10-01(af854a3a-2127-422b-91ae-364da2661108)
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.7(af854a3a-2127-422b-91ae-364da2661108)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.