CVE-2017-15299 describes a NULL pointer dereference vulnerability in the Linux kernel's KEYS subsystem, affecting versions up to 4.13.7. A local attacker can exploit this flaw by crafting a system call related to key management, leading to a denial of service and system crash. Rated Medium severity (CVSS 5.5), this vulnerability requires local access and has a high impact on availability, with no impact on confidentiality or integrity. There is no known public exploit code, active exploitation, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.13.6CPE matchmatch criteria | cpe:2.3:o:linux:linux_kernel:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.