Fix EINPROGRESS notification callback in kernel-crypto CVE-2017-7618 remote

asked 2017-06-01

updated 2017-06-01

crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue. 7.5 high (attack range: remote)

Patch is available.

file affected: kernel-adaptation-sbj- ahash.c /include/crypto/internal/hash.h

