CVEs Blog | G5 Cyber Security

CVE-2014-9644 – The Crypto API in the Linux kernel before 3.18.5 allows local users to lo

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.

 

Source: https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2014-9644

Reference (s):

Exit mobile version