CVE-2015-8970 PUBLISHED

crypto/algif_skcipher.c in the Linux kernel before 4.4.2 does not verify that a setkey operation has been performed on an AF_ALG socket before an accept system call is processed, which allows local users to cause a denial of service (NULL pointer dereference and system crash) via a crafted application that does not supply a key, related to the lrw_crypt function in crypto/lrw.c.

EPSS 0.04% · 11.4th percentile

Risk Scores

EPSS Score
0.04%
11.4th percentile

Affected Products

VendorProductVersions
Ubuntu:22.04:LTSlinux-realtime0, 5.15.0-1032.35
Ubuntu:14.04:LTSlinux-lts-vivid3.19.0-58.64~14.04.1, 3.19.0-56.62~14.04.1, 3.19.0-51.58~14.04.1
Ubuntu:20.04:LTSlinux-raspi25.4.0-1006.6, 5.4.0-1004.4, 5.3.0-1017.19
Ubuntu:22.04:LTSlinux-intel-iot-realtime5.15.0-1073.75, 0
Ubuntu:20.04:LTSlinux-riscv5.4.0-36.41, 5.4.0-37.42, 5.4.0-39.44
Ubuntu:22.04:LTSlinux-riscv5.15.0-1015.17, 5.15.0-1014.16, 5.15.0-1012.13
Ubuntu:Pro:14.04:LTSlinux3.13.0-63.103, 3.13.0-65.105, 3.13.0-65.106
Ubuntu:20.04:LTSlinux-azure-fde5.4.0-1090.95+cvm1.1, 0, 5.4.0-1063.66+cvm2.2
Ubuntu:20.04:LTSlinux-gke5.4.0-1103.110, 5.4.0-1102.109, 5.4.0-1104.111
Ubuntu:20.04:LTSlinux-gkeop5.4.0-1075.79, 5.4.0-1076.80, 5.4.0-1077.81
Ubuntu:24.04:LTSlinux-raspi-realtime0, 6.8.0-2019.20
Ubuntu:20.04:LTSlinux-gkeop-5.155.15.0-1053.60~20.04.1, 5.15.0-1052.59~20.04.1, 5.15.0-1051.58~20.04.1

Timeline

References

Open in Interactive Console →