Beveiligingsadvies

CVE-2014-9644

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2015-03-02 11:00:00
Laatst bijgewerkt 2024-08-06 13:47:41
Toegewezen door mitre
CVSS-score geen score
Status PUBLISHED

Beschrijving

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.