MEDIUM
security flaw
Published Apr 10, 2006
4.9
MEDIUMCVSS 2.0
EPSS 0.45%
Description
The sys_add_key function in the keyring code in Linux kernel 2.6.16.1 and 2.6.17-rc1, and possibly earlier versions, allows local users to cause a denial of service (OOPS) via keyctl requests that add a key to a user key instead of a keyring key, which causes an invalid dereference in the __keyring_search_one function.
Affected products
No data.
OR
- 2.6.16.1
- 2.6.17
No data.
Red Hat Enterprise Linux 4
kernel-0:2.6.9-34.0.1.EL
Fixed · RHSA-2006:0493
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 4 | kernel-0:2.6.9-34.0.1.EL | Fixed | RHSA-2006:0493 |
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (25)
- http://kernel.org/pub/linux/kernel/v2.6/ChangeLog-2.6.16.3 x_refsource_CONFIRM
- http://lwn.net/Alerts/180820/ vendor-advisoryx_refsource_FEDORA
- http://secunia.com/advisories/19573 third-party-advisoryx_refsource_SECUNIAPatchVendor Advisory
- http://secunia.com/advisories/19735 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20157 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20237 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/20716 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://secunia.com/advisories/21745 third-party-advisoryx_refsource_SECUNIAVendor Advisory
- http://support.avaya.com/elmodocs2/security/ASA-2006-161.htm x_refsource_CONFIRMVendor Advisory
- http://www.kernel.org/git/?p=linux/kernel/git/torvalds/linux-2.6.git%3Ba=commit%3Bh=c3a9d6541f84ac3ff566982d08389b87c1c36b4e x_refsource_CONFIRM
- http://www.mandriva.com/security/advisories?name=MDKSA-2006:086 vendor-advisoryx_refsource_MANDRIVA
- http://www.osvdb.org/24507 vdb-entryx_refsource_OSVDB
- http://www.redhat.com/support/errata/RHSA-2006-0493.html vendor-advisoryx_refsource_REDHAT
- http://www.securityfocus.com/bid/17451 vdb-entryx_refsource_BIDPatch
- http://www.ubuntu.com/usn/usn-302-1 vendor-advisoryx_refsource_UBUNTU
- http://www.vupen.com/english/advisories/2006/1307 vdb-entryx_refsource_VUPENVendor Advisory
- http://www.vupen.com/english/advisories/2006/1475 vdb-entryx_refsource_VUPENVendor Advisory
- https://access.redhat.com/security/cve/CVE-2006-1522 Vendor Advisory
- https://bugzilla.redhat.com/bugzilla/show_bug.cgi?id=188466 x_refsource_CONFIRMPatch
- https://bugzilla.redhat.com/show_bug.cgi?id=1618040 Issue Tracking
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2006-1526 Advisory
- https://exchange.xforce.ibmcloud.com/vulnerabilities/25722 vdb-entryx_refsource_XF
- https://nvd.nist.gov/vuln/detail/CVE-2006-1522
- https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A9325 vdb-entrysignaturex_refsource_OVAL
- https://www.cve.org/CVERecord?id=CVE-2006-1522
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Apr 10, 2006
Updated Aug 7, 2024
Reserved Mar 30, 2006
Link CVE-2006-1522
CISA Vulnrichment
No data
GitHub
No data