Medium severity5.5NVD Advisory· Published Nov 22, 2017· Updated May 13, 2026
CVE-2017-12193
CVE-2017-12193
Description
The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demonstrated by the keyring key type, and key addition and link creation operations.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/nvdIssue TrackingPatch
- github.com/torvalds/linux/commit/ea6789980fdaa610d7eb63602c746bf6ec70cd2bnvdPatchVendor Advisory
- www.securityfocus.com/bid/101678nvdThird Party AdvisoryVDB Entry
- www.kernel.org/pub/linux/kernel/v4.x/ChangeLog-4.13.11nvdIssue Tracking
- bugzilla.redhat.com/show_bug.cginvdIssue Tracking
- access.redhat.com/errata/RHSA-2018:0151nvd
- usn.ubuntu.com/3698-1/nvd
- usn.ubuntu.com/3698-2/nvd
News mentions
0No linked articles in our index yet.