CVE-2017-18075: Canonical Ubuntu Linux

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

crypto/pcrypt.c in the Linux kernel before 4.14.13 mishandles freeing instances, allowing a local user able to access the AF_ALG-based AEAD interface (CONFIG_CRYPTO_USER_API_AEAD) and pcrypt (CONFIG_CRYPTO_PCRYPT) to cause a denial of service (kfree of an incorrect pointer) or possibly have unspecified other impact by executing a crafted sequence of system calls.

Affected products

  • Canonical Ubuntu Linux: version 14.04 only; version 16.04 only
  • Linux Linux Kernel: from 4.2, before 4.4.111 (fixed in 4.4.111); from 4.5, before 4.9.76 (fixed in 4.9.76); from 4.10, before 4.14.13 (fixed in 4.14.13)

Published 2018-01-24. Last modified 2026-06-17.