Not a U.S. government website. NDD is an independent vulnerability database by Volerion and is not affiliated with or endorsed by NIST or NVD.
VOLERION
Volerion Security Research

NOT DEFERRED DATABASE

VULNERABILITIES

CVE-2016-10147 Details

Description

crypto/mcryptd.c in the Linux kernel before 4.8.15 allows local users to cause a denial of service (NULL pointer dereference and system crash) by using an AF_ALG socket with an incompatible algorithm, as demonstrated by mcryptd(md5).

Metrics

CVSS 3.x Severity and Vector Strings:

References to Advisories, Solutions, and Tools

By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.

URLSource(s)Tag(s)
http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=48a992727d82cb7db076fa15d372178743b1f4cd CVEIssue TrackingPatchThird Party Advisory
http://marc.info/?l=linux-crypto-vger&m=148063683310477&w=2 CVEThird Party Advisory
https://access.redhat.com/errata/RHSA-2017:1842 CVE
https://access.redhat.com/errata/RHSA-2017:2077 CVE
https://bugzilla.redhat.com/show_bug.cgi?id=1404200 CVEIssue Tracking

see all 18 references

Weakness Enumeration

CWE-IDCWE NameSource
CWE-476NULL Pointer Dereference[email protected]

Affected Products

ProductVersions
linux linux kernel
<= 4.8.14

CPE

  • cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:*

Remediation

  • No remediation found in references.

Change History

9 change records found show changes


QUICK INFO

CVE Dictionary Entry:
CVE-2016-10147
NVD Published Date:
Jan 18, 2017
NVD Last Modified:
Jun 17, 2026
Source:
[email protected]
CVE-2016-10147 Details - Not Deferred