CVE-2017-7374
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic transform objects to be freed prematurely.
Vulnerabilidad de uso después de liberación de memoria en fs/crypto/ en el kernel de Linux en versiones anteriores a 4.10.7 permite a usuarios locales provocar una denegación de servicio (referencia a puntero NULL) o posiblemente obtener privilegios revocando el llavero de claves utilizado para cifrado ext4, f2fs o ubifs, provocando que los objetos de transformación criptográfica sean liberados prematuramente.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2017-03-31 CVE Reserved
- 2017-03-31 CVE Published
- 2019-10-26 First Exploit
- 2023-03-08 EPSS Updated
- 2024-08-05 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-416: Use After Free
- CWE-476: NULL Pointer Dereference
CAPEC
References (6)
URL | Tag | Source |
---|---|---|
http://www.securityfocus.com/bid/97308 | Third Party Advisory | |
https://source.android.com/security/bulletin/2017-10-01 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://github.com/ww9210/cve-2017-7374 | 2019-10-26 |
URL | Date | SRC |
---|---|---|
https://www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.10.7 | 2023-02-14 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.2 < 4.4.59 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.2 < 4.4.59" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.5 < 4.9.20 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.5 < 4.9.20" | - |
Affected
| ||||||
Linux Search vendor "Linux" | Linux Kernel Search vendor "Linux" for product "Linux Kernel" | >= 4.10 < 4.10.7 Search vendor "Linux" for product "Linux Kernel" and version " >= 4.10 < 4.10.7" | - |
Affected
|