← back
CVE-2017-12193

CVE-2017-12193

EPSS 0.5%CWE-476
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 0.5%KEV nãoPoC Nuclei Metasploit Patch referenciado
Lifecycle
22 Nov 2017Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demonstrated by the keyring key type, and key addition and link creation operations.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →