CVE-2018-14619: Linux Kernel

High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.

A flaw was found in the crypto subsystem of the Linux kernel before version kernel-4.15-rc4. The "null skcipher" was being dropped when each af_alg_ctx was freed instead of when the aead_tfm was freed. This can cause the null skcipher to be freed while it is still in use leading to a local user being able to crash the system or possibly escalate privileges.

Affected products

  • Linux Linux Kernel: from 4.14, before 4.14.8 (fixed in 4.14.8); version 4.15 only

Published 2018-08-30. Last modified 2026-06-17.