kernel: Uninitialized variable in request_key handling causes kernel crash in error handling path
Published Jun 27, 2016
7.8
HIGHCVSS 3.0
EPSS 0.58%
Description
The key_reject_and_link function in security/keys/key.c in the Linux kernel through 4.6.3 does not ensure that a certain data structure is initialized, which allows local users to cause a denial of service (system crash) via vectors involving a crafted keyctl request2 command.
Affected products
No data.
Configuration 3
- ≤ 4.6.3
Configuration 4
Configuration 5
- 6.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.0
- 7.2
- 7.2
- 7.0
- 2.0
No data.
Red Hat Enterprise Linux 6
kernel-0:2.6.32-642.6.1.el6
Fixed · RHSA-2016:2006
Red Hat Enterprise Linux 6.4 Advanced Update Support
kernel-0:2.6.32-358.75.1.el6
Fixed · RHSA-2016:2133
Red Hat Enterprise Linux 6.5 Advanced Update Support
kernel-0:2.6.32-431.74.1.el6
Fixed · RHSA-2016:2074
Red Hat Enterprise Linux 6.6 Extended Update Support
kernel-0:2.6.32-504.54.1.el6
Fixed · RHSA-2016:2128
Red Hat Enterprise Linux 6.7 Extended Update Support
kernel-0:2.6.32-573.35.1.el6
Fixed · RHSA-2016:2076
Red Hat Enterprise Linux 7
kernel-0:3.10.0-327.28.2.el7
Fixed · RHSA-2016:1539
Red Hat Enterprise Linux 7
kernel-rt-0:3.10.0-327.28.2.rt56.234.el7_2
Fixed · RHSA-2016:1541
Red Hat Enterprise Linux 7.1 Extended Update Support
kernel-0:3.10.0-229.40.1.ael7b
Fixed · RHSA-2016:1657
Red Hat Enterprise MRG 2
kernel-rt-1:3.10.0-327.rt56.194.el6rt
Fixed · RHSA-2016:1532
Red Hat Enterprise Linux 5
kernel
Not affected
| Product | Package | State | Advisory |
|---|---|---|---|
| Red Hat Enterprise Linux 6 | kernel-0:2.6.32-642.6.1.el6 | Fixed | RHSA-2016:2006 |
| Red Hat Enterprise Linux 6.4 Advanced Update Support | kernel-0:2.6.32-358.75.1.el6 | Fixed | RHSA-2016:2133 |
| Red Hat Enterprise Linux 6.5 Advanced Update Support | kernel-0:2.6.32-431.74.1.el6 | Fixed | RHSA-2016:2074 |
| Red Hat Enterprise Linux 6.6 Extended Update Support | kernel-0:2.6.32-504.54.1.el6 | Fixed | RHSA-2016:2128 |
| Red Hat Enterprise Linux 6.7 Extended Update Support | kernel-0:2.6.32-573.35.1.el6 | Fixed | RHSA-2016:2076 |
| Red Hat Enterprise Linux 7 | kernel-0:3.10.0-327.28.2.el7 | Fixed | RHSA-2016:1539 |
| Red Hat Enterprise Linux 7 | kernel-rt-0:3.10.0-327.28.2.rt56.234.el7_2 | Fixed | RHSA-2016:1541 |
| Red Hat Enterprise Linux 7.1 Extended Update Support | kernel-0:3.10.0-229.40.1.ael7b | Fixed | RHSA-2016:1657 |
| Red Hat Enterprise MRG 2 | kernel-rt-1:3.10.0-327.rt56.194.el6rt | Fixed | RHSA-2016:1532 |
| Red Hat Enterprise Linux 5 | kernel | Not affected | n/a |
No package ranges for this CVE.
Remediation
Red Hat statement
This issue affects the Linux kernels as shipped with Red Hat Enterprise Linux 6 and may be addressed in a future update. This issue does not affect the Linux kernel packages as shipped with Red Hat Enterprise Linux 7 and Red Hat Enterprise MRG 2 as the due updates to fix this issue have been shipped now.
Metrics
No CVSS v4.0 score for this CVE.
No CVSS v3.1 score for this CVE.
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
1 other source (Red Hat) ▾
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
AV:L/AC:L/Au:N/C:N/I:N/A:C
This CVE is not in the KEV list.
No CISA SSVC assessment for this CVE yet.
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2022–2026- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v2
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (10 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.58% (0.00582) | 45.79th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.59% (0.00587) | 43.23th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.05% (0.00051) | 12.91th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.05% (0.00046) | 19.07th | v3 (v2023.03.01) |
| May 8, 2024 | 0.05% (0.00046) | 16.07th | v3 (v2023.03.01) |
| Mar 7, 2023 | 0.05% (0.00046) | 14.05th | v3 (v2023.03.01) |
| Mar 6, 2023 | 1.55% (0.01547) | 74.98th | v2 (v2022.01.01) |
| Feb 23, 2023 | 1.55% (0.01547) | 74.94th | v2 (v2022.01.01) |
| Apr 1, 2022 | 1.55% (0.01547) | 72.92th | v2 (v2022.01.01) |
| Feb 4, 2022 | 1.55% (0.01547) | 51.82th | v2 (v2022.01.01) |
References (51)
- http://git.kernel.org/cgit/linux/kernel/git/torvalds/linux.git/commit/?id=38327424b40bcebe2de92d07312c89360ac9229a x_refsource_CONFIRMVendor Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00000.html vendor-advisoryx_refsource_SUSEThird Party Advisory
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00003.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00007.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00008.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00009.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00012.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00013.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00014.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00015.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00016.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00017.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00018.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00019.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00020.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00021.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00022.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00023.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00026.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00027.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00044.html vendor-advisoryx_refsource_SUSE
- http://lists.opensuse.org/opensuse-security-announce/2016-08/msg00055.html vendor-advisoryx_refsource_SUSE
- http://rhn.redhat.com/errata/RHSA-2016-1532.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1539.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1541.html vendor-advisoryx_refsource_REDHATThird Party Advisory
- http://rhn.redhat.com/errata/RHSA-2016-1657.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-2006.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-2074.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-2076.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-2128.html vendor-advisoryx_refsource_REDHAT
- http://rhn.redhat.com/errata/RHSA-2016-2133.html vendor-advisoryx_refsource_REDHAT
- http://www.debian.org/security/2016/dsa-3607 vendor-advisoryx_refsource_DEBIAN
- http://www.openwall.com/lists/oss-security/2016/06/15/11 mailing-listx_refsource_MLIST
- http://www.oracle.com/technetwork/topics/security/linuxbulletinjul2016-3090544.html x_refsource_CONFIRMThird Party Advisory
- http://www.oracle.com/technetwork/topics/security/linuxbulletinoct2016-3090545.html x_refsource_CONFIRM
- http://www.oracle.com/technetwork/topics/security/ovmbulletinjul2016-3090546.html x_refsource_CONFIRMVendor Advisory
- http://www.securitytracker.com/id/1036763 vdb-entryx_refsource_SECTRACK
- http://www.ubuntu.com/usn/USN-3049-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-3050-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-3051-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-3052-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-3053-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-3054-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-3055-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-3056-1 vendor-advisoryx_refsource_UBUNTU
- http://www.ubuntu.com/usn/USN-3057-1 vendor-advisoryx_refsource_UBUNTU
- https://access.redhat.com/security/cve/CVE-2016-4470 Vendor Advisory
- https://bugzilla.redhat.com/show_bug.cgi?id=1341716 x_refsource_CONFIRMIssue TrackingThird Party AdvisoryVDB Entry
- https://github.com/torvalds/linux/commit/38327424b40bcebe2de92d07312c89360ac9229a x_refsource_CONFIRMVendor Advisory
- https://nvd.nist.gov/vuln/detail/CVE-2016-4470
- https://www.cve.org/CVERecord?id=CVE-2016-4470
Change history (0)
No recorded changes yet.