The rngapi_reset function in crypto/rng.c in the Linux kernel before 4.2 allows attackers to cause a denial of service (NULL pointer dereference).
The product dereferences a pointer that it expects to be valid but is NULL.
Link | Tags |
---|---|
https://bugzilla.redhat.com/show_bug.cgi?id=1485815 | issue tracking permissions required |
https://bugzilla.redhat.com/show_bug.cgi?id=1514609 | issue tracking |
https://access.redhat.com/errata/RHSA-2018:1062 | vendor advisory |
https://access.redhat.com/errata/RHSA-2018:0676 | vendor advisory |
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=94f1bb15bed84ad6c893916b7e7b9db6f1d7eec6 | patch vendor advisory |
https://github.com/torvalds/linux/commit/94f1bb15bed84ad6c893916b7e7b9db6f1d7eec6 | patch vendor advisory |