CVE-2015-3331
Summary
The __driver_rfc4106_decrypt function in arch/x86/crypto/aesni-intel_glue.c in the Linux kernel before 3.19.3 does not properly determine the memory locations used for encrypted data, which allows context-dependent attackers to cause a denial of service (buffer overflow and system crash) or possibly execute arbitrary code by triggering a crypto API call, as demonstrated by use of a libkcapi test program with an AF_ALG(aead) socket.
Impact & exploitability
AV:N/AC:M/Au:N/C:C/I:C/A:C
Affected products we track (1)
Recommendation
Apply the vendor fix promptly. Open any affected product above for its exact safe version.
Additional information
- NVD record
- http://git.kernel.org/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=ccfe8c3f7e52ae83155cb038753f4c75b774ca8a
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00004.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00007.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00008.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00009.htmlAdvisory
- http://lists.opensuse.org/opensuse-security-announce/2015-09/msg00011.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2015-1081.htmlAdvisory
- http://rhn.redhat.com/errata/RHSA-2015-1199.htmlAdvisory