View at Official suse advisory, NVD, CVE.org · CVE detail
Freshness: upstream tracker timestamp is available; use API updated time as primary recency signal.
CVE-2017-17806 severity low: SUSE including 237 source package names (cluster-md-kmp-default-4.12.14-120.1, cluster-md-kmp-default-4.4.103-6.38.1, …), 613 product×package rows across 98 product lines (SUSE CaaS Platform 4.0, SUSE CaaS Platform 4.5, … (98 product lines)): Fixed 343, Known Not Affected 270.
The HMAC implementation (crypto/hmac.c) in the Linux kernel before 4.14.8 does not validate that the underlying cryptographic hash algorithm is unkeyed, allowing a local attacker able to use the AF_ALG-based hash interface (CONFIG_CRYPTO_USER_API_HASH) and the SHA-3 hash algorithm (CONFIG_CRYPTO_SHA3) to cause a kernel stack buffer overflow by executing a crafted sequence of system calls that encounter a missing SHA-3 initialization.