Lucene search

K
redhatcveRedhat.comRH:CVE-2017-17805
HistoryOct 19, 2019 - 6:30 a.m.

CVE-2017-17805

2019-10-1906:30:55
redhat.com
access.redhat.com
23

0.0004 Low

EPSS

Percentile

10.3%

The Salsa20 encryption algorithm in the Linux kernel, before 4.14.8, does not correctly handle zero-length inputs. This allows a local attacker the ability to use the AF_ALG-based skcipher interface to cause a denial of service (uninitialized-memory free and kernel crash) or have an unspecified other impact by executing a crafted sequence of system calls that use the blkcipher_walk API. Both the generic implementation (crypto/salsa20_generic.c) and x86 implementation (arch/x86/crypto/salsa20_glue.c) of Salsa20 are vulnerable.