Use-after-free vulnerability in fs/crypto/ in the Linux kernel before 4.10.7 allows local users to cause a denial of service (NULL pointer dereference) or possibly gain privileges by revoking keyring keys being used for ext4, f2fs, or ubifs encryption, causing cryptographic transform objects to be freed prematurely.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 4.2 | 4.4.59 |
| linux / linux_kernel | 4.5 | 4.9.20 |
| linux / linux_kernel | 4.10 | 4.10.7 |