CVE-2016-9313: Linux Kernel
High severity, CVSS 7.8. EPSS: 2.1% chance of exploitation in the next 30 days.
security/keys/big_key.c in the Linux kernel before 4.8.7 mishandles unsuccessful crypto registration in conjunction with successful key-type registration, which allows local users to cause a denial of service (NULL pointer dereference and panic) or possibly have unspecified other impact via a crafted application that uses the big_key data type.
Affected products
- Linux Linux Kernel: from 4.7, before 4.8.7 (fixed in 4.8.7)
Published 2016-11-28. Last modified 2026-06-17.