Fix EINPROGRESS notification callback in kernel-crypto CVE-2017-7618 remote

Tracked by Jolla (In progress)

asked 2017-06-01 12:34:42 +0200

this post is marked as community wiki

This post is a wiki. Anyone with karma >75 is welcome to improve it.

updated 2017-06-01 12:34:42 +0200

lpr gravatar image

Description

crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue. 7.5 high (attack range: remote)

Patch is available.

file affected: kernel-adaptation-sbj-3.4.108.20161101.1/crypto/ ahash.c /include/crypto/internal/hash.h

edit retag flag offensive close delete