Follow @Openwall on Twitter for new release announcements and other news
[<prev] [next>] [day] [month] [year] [list]
Date: Tue, 15 Nov 2016 12:25:35 +1000
From: Wade Mealing <>
Subject: CVE-2016-8646: linux kernel - oops in shash_async_export()


Igor Redko from Virtuozzo found a vulnerability was found in the Linux
kernel. An unprivileged local user could triger oops in
shash_async_export() by attempting to force the in-kernel hashing
algorithms into decrypting an empty data set.  Not all in kernel algorithms
are affected.

Upstream has already fixed this issue (See upstream patch) in 4.4rc1.


Wade Mealing
Red Hat Product Security

Upstream discussion:

Upstream patch:

Red Hat Bugzilla:

Powered by blists - more mailing lists

Please check out the Open Source Software Security Wiki, which is counterpart to this mailing list.

Confused about mailing lists and their use? Read about mailing lists on Wikipedia and check out these guidelines on proper formatting of your messages.