Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

debian логотип

CVE-2017-15299

Опубликовано: 14 окт. 2017
Источник: debian
EPSS Низкий

Описание

The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uninstantiated, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted system call.

Пакеты

ПакетСтатусВерсия исправленияРелизТип
linuxfixed4.13.10-1package
linuxfixed4.9.65-1stretchpackage
linuxfixed3.16.51-1jessiepackage

Примечания

  • Fixed by: https://git.kernel.org/linus/60ff5b2f547af3828aebafd54daded44cfb0807a (4.14-rc6)

EPSS

Процентиль: 1%
0.00011
Низкий

Связанные уязвимости

CVSS3: 5.5
ubuntu
больше 7 лет назад

The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uninstantiated, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted system call.

CVSS3: 5.5
redhat
больше 7 лет назад

The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uninstantiated, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted system call.

CVSS3: 5.5
nvd
больше 7 лет назад

The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uninstantiated, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted system call.

CVSS3: 5.5
github
около 3 лет назад

The KEYS subsystem in the Linux kernel through 4.13.7 mishandles use of add_key for a key that already exists but is uninstantiated, which allows local users to cause a denial of service (NULL pointer dereference and system crash) or possibly have unspecified other impact via a crafted system call.

CVSS3: 5.5
fstec
больше 7 лет назад

Уязвимость подсистемы KEYS ядра операционной системы Linux, позволяющая нарушителю вызвать отказ в обслуживании

EPSS

Процентиль: 1%
0.00011
Низкий
Уязвимость CVE-2017-15299