Upstream information
Description
The Crypto API in the Linux kernel before 3.18.5 allows local users to load arbitrary kernel modules via a bind system call for an AF_ALG socket with a parenthesized module template expression in the salg_name field, as demonstrated by the vfat(aes) expression, a different vulnerability than CVE-2013-7421.SUSE information
Overall state of this security issue: Does not affect SUSE products
| CVSS detail | National Vulnerability Database |
|---|---|
| Base Score | 2.1 |
| Vector | AV:L/AC:L/Au:N/C:N/I:P/A:N |
| Access Vector | Local |
| Access Complexity | Low |
| Authentication | None |
| Confidentiality Impact | None |
| Integrity Impact | Partial |
| Availability Impact | None |
List of released packages
| Product(s) | Fixed package version(s) | References |
|---|---|---|
| SUSE Liberty Linux 7 |
| Patchnames: RHSA-2015:2152 |
SUSE Timeline for this CVE
CVE page created: Fri Jan 23 08:26:54 2015CVE page last modified: Mon Oct 6 18:21:44 2025