The Linux kernel 4.14.67 mishandles certain interaction among XFRM Netlink messages, IPPROTO_AH packets, and IPPROTO_IP packets, which allows local users to cause a denial of service (memory consumption and system hang) by leveraging root access to execute crafted applications, as demonstrated on CentOS 7.
| Software | From | Fixed in |
|---|---|---|
| linux / linux_kernel | 4.14.67 | 4.14.67.x |