Back

HIGH

kernel: Possible use-after-free vulnerability in keyring facility

Published Feb 8, 2016

Description

The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.

Affected products

Remediation

Red Hat statement

This issue does not affect the Linux kernels as shipped with Red Hat Enterprise Linux 5 and 6. Refer to https://access.redhat.com/node/2131021 for further information.

Metrics

Weaknesses (1)

References (46)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner redhat
Published Feb 8, 2016
Updated Aug 5, 2024
Reserved Dec 16, 2015
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity Important
Public date Jan 19, 2016