Back

HIGH

kernel: local privesc in key management

Published Feb 8, 2016

Description

The KEYS subsystem in the Linux kernel before 4.4 allows local users to gain privileges or cause a denial of service (BUG) via crafted keyctl commands that negatively instantiate a key, related to security/keys/encrypted-keys/encrypted.c, security/keys/trusted.c, and security/keys/user_defined.c.

Affected products

Remediation

Red Hat statement

This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 4 and 5. This issue does affect the kernels shipped with Red Hat Enterprise Linux 6, 7, MRG-2 and realtime kernels and plans to be addressed in a future update.

Metrics

References (28)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner mitre
Published Feb 8, 2016
Updated Aug 6, 2024
Reserved Dec 10, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Dec 9, 2015