CVE-2017-12192: Linux Kernel
Medium severity, CVSS 5.5. EPSS: 0.4% chance of exploitation in the next 30 days.
The keyctl_read_key function in security/keys/keyctl.c in the Key Management subcomponent in the Linux kernel before 4.13.5 does not properly consider that a key may be possessed but negatively instantiated, which allows local users to cause a denial of service (OOPS and system crash) via a crafted KEYCTL_READ operation.
Affected products
- Linux Linux Kernel: up to and including 4.13.4
Published 2017-10-12. Last modified 2026-06-17.