The assoc_array_insert_into_terminal_node function in lib/assoc_array.c in the Linux kernel before 4.13.11 mishandles node splitting, which allows local users to cause a denial of service (NULL pointer dereference and panic) via a crafted application, as demonstrated by the keyring key type, and key addition and link creation operations.
3.13.0-153.2034.4.0-1005.54.4.0-103.126~14.04.14.4.0-103.1264.4.0-1043.524.13.0-1005.74.13.0-1002.54.13.0-32.35~16.04.14.4.0-1012.174.13.0-1010.11Exploitability
AV:LAC:LPR:LUI:NScope
S:UImpact
C:NI:NA:HCVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H