CVE-2014-3631
HIGH 7.2EPSS 1.0%
The assoc_array_gc function in the associative-array implementation in lib/assoc_array.c in the Linux kernel before 3.16.3 does not properly implement garbage collection, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via multiple "keyctl newring" operations followed by a "keyctl timeout" operation.
- CVSS v2.0
- 7.2 HIGH
AV:L/AC:L/Au:N/C:C/I:C/A:C - EPSS
- 0.96% chance of exploitation in the next 30 days, 59th percentile
- Published
- 2014-09-28
- Updated
- 2024-08-06