We have moved to a new Sailfish OS Forum. Please start new discussions there.

Revision history [back]

click to hide/show revision 1
initial version

posted 2017-06-01 12:34:42 +0200

Fix EINPROGRESS notification callback in kernel-crypto CVE-2017-7618 remote

Description

crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue. 7.5 high (attack range: remote)

Patch is available.

file affected: kernel-adaptation-sbj-3.4.108.20161101.1/crypto/ ahash.c /include/crypto/internal/hash.h