Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2016-0728

Опубликовано: 08 фев. 2016
Источник: debian
EPSS Средний

Описание

The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.3.3-6package
linuxnot-affectedwheezypackage
linux-2.6not-affectedpackage

Примечания

  • Upstream commit: https://git.kernel.org/linus/23567fd052a9abb6d67fe8e7a9ccdd9800a540f2

  • Introduced in https://git.kernel.org/linus/3a50597de8635cd05133bd12c95681c82fe7b878 (v3.8-rc1)

  • http://perception-point.io/2016/01/14/analysis-and-exploitation-of-a-linux-kernel-vulnerability-cve-2016-0728/

EPSS

Процентиль: 98%
0.5601
Средний

Связанные уязвимости

CVSS3: 7.8
ubuntu
больше 9 лет назад

The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.

redhat
больше 9 лет назад

The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.

CVSS3: 7.8
nvd
больше 9 лет назад

The join_session_keyring function in security/keys/process_keys.c in the Linux kernel before 4.4.1 mishandles object references in a certain error case, which allows local users to gain privileges or cause a denial of service (integer overflow and use-after-free) via crafted keyctl commands.

suse-cvrf
больше 9 лет назад

Security update for Kernel live patch 10

suse-cvrf
больше 9 лет назад

Security update for the Linux Kernel

EPSS

Процентиль: 98%
0.5601
Средний