Oval Definition:oval:com.ubuntu.artful:def:201610147000
Revision Date:2017-01-18Version:1
Title:CVE-2016-10147 on Ubuntu 17.10 (artful) - low.
Description:crypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an AF_ALG socket with an incompatible algorithm, as demonstrated by mcryptd(md5). Mikulas Patocka discovered that the asynchronous multibuffer cryptographic daemon (mcryptd) in the Linux kernel did not properly handle being invoked with incompatible algorithms. A local attacker could use this to cause a denial of service (system crash).
Family:unixClass:vulnerability
Status:Reference(s):CVE-2016-10147
Platform(s):Ubuntu 17.10
Product(s):
Definition Synopsis
  • Ubuntu 17.10 (artful) is installed.
  • AND Package Information
  • NOT While related to the CVE in some way, the 'linux' package in artful is not affected (note: '4.10.0-19.21').
  • OR NOT While related to the CVE in some way, the 'linux-raspi2' package in artful is not affected (note: '4.10.0-1004.6').
  • OR NOT While related to the CVE in some way, the 'linux-snapdragon' package in artful is not affected (note: '4.4.0-1050.54').
  • BACK