Medium severity5.5NVD Advisory· Published Oct 14, 2017· Updated May 13, 2026
CVE-2017-15299
CVE-2017-15299
Description
The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uninstantiated, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted system call.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
8- marc.infonvdIssue TrackingPatchThird Party Advisory
- marc.infonvdIssue TrackingPatchThird Party Advisory
- bugzilla.redhat.com/show_bug.cginvdIssue TrackingThird Party Advisory
- access.redhat.com/errata/RHSA-2018:0654nvd
- lists.debian.org/debian-lts-announce/2017/12/msg00004.htmlnvd
- usn.ubuntu.com/3798-1/nvd
- usn.ubuntu.com/3798-2/nvd
- www.mail-archive.com/linux-kernel%40vger.kernel.org/msg1499828.htmlnvd
News mentions
0No linked articles in our index yet.