crypto/ahash.c in the Linux kernel through 4.10.9 allows attackers to cause a denial of service (API operation calling its own callback, and infinite recursion) by triggering EBUSY on a full queue.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 3.19 | 4.1.40 |
| linux / linux_kernel | 3.15 | 3.16.44 |
| linux / linux_kernel | 3.17 | 3.18.50 |
| linux / linux_kernel | 4.5 | 4.9.24 |
| linux / linux_kernel | 4.10 | 4.10.12 |
| linux / linux_kernel | 4.2 | 4.4.63 |