Lucene search

K
prionPRIOn knowledge basePRION:CVE-2014-9644
HistoryMar 02, 2015 - 11:59 a.m.

Design/Logic Flaw

2015-03-0211:59:00
PRIOn knowledge base
www.prio-n.com
12

6.2 Medium

AI Score

Confidence

Low

0.0004 Low

EPSS

Percentile

10.1%

The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.

References